Rewterz

Bitter APT – Active IOCs

November 20, 2024
Rewterz

An Emerging Ducktail Infostealer – Active IOCs

November 20, 2024

CVE-2024-51503 – Trend Micro Deep Security Agent Zero-Day Vulnerabilitiy

Severity

High

Analysis Summary

CVE-2024-51503

A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain.

Impact

  • Privilege Escalation
  • Code Execution

Indicators of Compromise

CVE

  • CVE-2024-51503

Affected Vendors

Trend Micro

Affected Products

  • Trend Micro Deep Security Agent 20.0

Remediation

Refer to Trend Micro Security Advisory for patch, upgrade, or suggested workaround information.

Trend Micro Security Advisory

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.