ZDI-CAN-25215: ZDI-24-1516: Trend Micro Deep Security Agent Manual Scan Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Deep Security Agent. Authentication is required to exploit this vulnerability. The specific flaw exists within the Trend Micro Deep Security Notifier service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Deep Security Agent. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-51503.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25215?
The severity of ZDI-CAN-25215 is characterized as critical due to its potential for remote code execution.
How do I fix ZDI-CAN-25215?
To fix ZDI-CAN-25215, ensure that you apply the latest security patches provided by Trend Micro for Deep Security Agent.
Does ZDI-CAN-25215 require authentication to exploit?
Yes, ZDI-CAN-25215 requires authentication to exploit the vulnerability.
What types of attacks can ZDI-CAN-25215 enable?
ZDI-CAN-25215 can enable remote attackers to execute arbitrary code on affected installations.
What versions of Trend Micro Deep Security are affected by ZDI-CAN-25215?
ZDI-CAN-25215 affects certain installations of Trend Micro Deep Security Agent, specific version details should be reviewed in the vendor's advisory.