ZDI-CAN-24557: ZDI-25-003: Trend Micro Apex One Security Agent Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-55632.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24557?
The severity of ZDI-CAN-24557 is considered high, as it allows local attackers to escalate privileges.
How do I fix ZDI-CAN-24557?
To fix ZDI-CAN-24557, update the Trend Micro Apex One Security Agent to the latest version as recommended by the vendor.
Who is affected by ZDI-CAN-24557?
ZDI-CAN-24557 affects installations of Trend Micro Apex One Security Agent that are not up to date with security patches.
What type of attack does ZDI-CAN-24557 facilitate?
ZDI-CAN-24557 facilitates local privilege escalation attacks, allowing an attacker to gain higher system access.
Is remote access needed to exploit ZDI-CAN-24557?
No, remote access is not needed; the attacker must first execute low-privileged code on the system.