Trend Micro Security Updates – 25 November 2024

Trend Micro has released security updates to address several vulnerabilities affecting Trend Micro Deep Security and Trend Micro Deep Discovery Inspector.

The addressed vulnerabilities could allow the attacker to obtain sensitive information or execute arbitrary code and gain elevated privilegesto the affected product.

Sample of the addressed vulnerabilities:

1. Trend Micro Deep Security Agent Manual Scan Command Injection RCE Vulnerability (CVE-2024-51503):

  • CVSS: 8.0
  • Attack Vector: Adjacent
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2024-46902
  • CVE-2024-46903
  • CVE-2024-48903
  • CVE-2024-51503
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Trend Micro Security Bulletin

References