ZDI-CAN-25681: ZDI-25-241: Trend Micro Deep Security Agent Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Deep Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Damage Cleanup Engine. By creating a junction, an attacker can abuse this component to delete a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Deep Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2025-30642.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ZDI-CAN-25681?
ZDI-CAN-25681 is a vulnerability in Trend Micro Deep Security Agent that allows local attackers to create a denial-of-service condition.
What is the severity of ZDI-CAN-25681?
The severity of ZDI-CAN-25681 is classified as high due to the potential for local denial-of-service attacks.
How do I fix ZDI-CAN-25681?
To fix ZDI-CAN-25681, update your Trend Micro Deep Security Agent to the latest version as provided by the vendor.
Who is affected by ZDI-CAN-25681?
Users of Trend Micro Deep Security Agent are affected by the ZDI-CAN-25681 vulnerability.
Can ZDI-CAN-25681 be exploited remotely?
No, ZDI-CAN-25681 can only be exploited by local attackers who have the ability to execute low-privileged code on the system.