ZDI-CAN-16568: ZDI-24-075: Trend Micro Deep Security Improper Access Control Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Deep Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Anti-Malware Solution Platform. The product applies insufficient access controls to a sensitive folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Deep Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-52337.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID ZDI-CAN-16568?
ZDI-CAN-16568 is a privilege escalation vulnerability in Trend Micro Deep Security that allows local attackers to gain higher privileges.
What is the severity level of ZDI-CAN-16568?
The severity level of ZDI-CAN-16568 is considered high due to the potential for local attackers to escalate privileges.
How can I mitigate the effects of ZDI-CAN-16568?
To mitigate ZDI-CAN-16568, ensure that Trend Micro Deep Security is updated to the latest version that addresses this vulnerability.
Who is affected by vulnerability ZDI-CAN-16568?
Users of Trend Micro Deep Security Agent who allow execution of low-privileged code are affected by ZDI-CAN-16568.
How can an attacker exploit ZDI-CAN-16568?
An attacker can exploit ZDI-CAN-16568 by first executing low-privileged code on a vulnerable system to escalate their privileges.