ZDI-25-241: Trend Micro Deep Security Agent Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Deep Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Damage Cleanup Engine. By creating a junction, an attacker can abuse this component to delete a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Deep Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2025-30642.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-241?
The severity of ZDI-25-241 is classified as high due to its potential for denial-of-service attacks.
How do I fix ZDI-25-241?
To fix ZDI-25-241, apply the latest security patches provided by Trend Micro for the Deep Security Agent.
Who is affected by ZDI-25-241?
Users of Trend Micro Deep Security Agent are affected by the ZDI-25-241 vulnerability.
Can ZDI-25-241 be exploited remotely?
No, ZDI-25-241 requires local access to the system to exploit the vulnerability.
What kind of impact does ZDI-25-241 have on systems?
ZDI-25-241 can create a denial-of-service condition, rendering the affected systems unusable.