Rewterz
North Korean APT Kimsuky Aka Black Banshee – Active IOCs
June 10, 2024
Rewterz
MuddyWater APT – Active IOCs
June 10, 2024

CVE-2024-36358 – Trend Micro Deep Security Agent Zero-Day Vulnerability

Severity

High

Analysis Summary

CVE-2024-36358

Trend Micro Deep Security Agent could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Trend Micro Anti-Malware Solution Platform. By using a specially crafted symlink, an authenticated attacker could exploit this vulnerability to gain elevated privileges and execute arbitrary code in the context of SYSTEM.

Impact

  • Privilege Escalation

Indicators of Compromise

CVE

  • CVE-2024-36358

Affected Vendors

Trend Micro

Affected Products

  • Trend Micro Deep Security Agent 20

Remediation

Refer to Trend Micro Security Advisory for patch, upgrade or suggested workaround information.

Trend Micro Security Advisory