An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| trendmicro / deep_security_agent | 20.0.1-update12510 | 20.0.1-update12510.x |
| trendmicro / deep_security_agent | 20.0.1-update14610 | 20.0.1-update14610.x |
| trendmicro / deep_security_agent | 20.0.1-update17380 | 20.0.1-update17380.x |
| trendmicro / deep_security_agent | 20.0.1-update19250 | 20.0.1-update19250.x |
| trendmicro / deep_security_agent | 20.0.1-update21510 | 20.0.1-update21510.x |
| trendmicro / deep_security_agent | 20.0.1-update9400 | 20.0.1-update9400.x |