A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| trendmicro / deep_security_agent | - | 20.0.1 |
| trendmicro / deep_security_agent | 20.0.1 | 20.0.1.x |
| trendmicro / deep_security_agent | 20.0.1-update12510 | 20.0.1-update12510.x |
| trendmicro / deep_security_agent | 20.0.1-update14610 | 20.0.1-update14610.x |
| trendmicro / deep_security_agent | 20.0.1-update17380 | 20.0.1-update17380.x |
| trendmicro / deep_security_agent | 20.0.1-update19250 | 20.0.1-update19250.x |
| trendmicro / deep_security_agent | 20.0.1-update21510 | 20.0.1-update21510.x |
| trendmicro / deep_security_agent | 20.0.1-update23340 | 20.0.1-update23340.x |
| trendmicro / deep_security_agent | 20.0.1-update3180 | 20.0.1-update3180.x |
| trendmicro / deep_security_agent | 20.0.1-update4540 | 20.0.1-update4540.x |
| trendmicro / deep_security_agent | 20.0.1-update690 | 20.0.1-update690.x |
| trendmicro / deep_security_agent | 20.0.1-update7380 | 20.0.1-update7380.x |
| trendmicro / deep_security_agent | 20.0.1-update9400 | 20.0.1-update9400.x |