CVE-2024-51503

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)

Published: Nov 19, 2024 / Updated: 9h ago

010
CVSS 8No EPSS yetHigh
CVE info copied to clipboard

A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other machines.

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Timeline

First Article

Feedly found the first article mentioning CVE-2024-51503. See article

Nov 18, 2024 at 10:38 PM / Security feed from CyberSecurity Help
CVSS Estimate

Feedly estimated the CVSS score as HIGH

Nov 18, 2024 at 10:39 PM
CVE Assignment

NVD published the first details for CVE-2024-51503

Nov 19, 2024 at 7:15 PM
CVSS

A CVSS base score of 8 has been assigned.

Nov 19, 2024 at 7:21 PM / nvd
Static CVE Timeline Graph

Affected Systems

Trendmicro/deep_security_agent
+null more

Attack Patterns

CAPEC-108: Command Line Execution through SQL Injection
+null more

News

NA - CVE-2024-51503 - A security agent manual scan command injection...
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected...
CVE-2024-51503 - Trend Micro Deep Security Agent Command Injection November 19, 2024 at 07:15PM https:// ift.tt/Asa2CXg # CVE # IOC # CTI # ThreatIntelligence # ThreatIntel # Cybersecurity # Recon
CVE-2024-51503 - Trend Micro Deep Security Agent Command Injection
CVE ID : CVE-2024-51503 Published : Nov. 19, 2024, 7:15 p.m. 15 minutes ago Description : A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other machines.
CVE-2024-51503
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other...
CVE-2024-51503
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other machines.
See 6 more articles and social media posts

CVSS V3.1

Attack Vector:Adjacent_network
Attack Complexity:High
Privileges Required:Low
User Interaction:None
Scope:Changed
Confidentiality:High
Integrity:High
Availability Impact:High

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI