Trend Micro Deep Security vulnerabilities
8 known vulnerabilities affecting trend_micro/trend_micro_deep_security.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2LOW3
Vulnerabilities
Page 1 of 1
CVE-2022-40710HIGHCVSS 7.8≥ 20.0, < 20.0.0.53942022-09-28
CVE-2022-40710 [HIGH] CWE-59 CVE-2022-40710: A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Age
A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
cvelistv5nvd
CVE-2022-40707LOWCVSS 3.3v202022-09-28
CVE-2022-40707 [LOW] CWE-125 CVE-2022-40707: An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Securit
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabili
cvelistv5nvd
CVE-2022-40709LOWCVSS 3.3v202022-09-28
CVE-2022-40709 [LOW] CVE-2022-40709: An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker t
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target sy
cvelistv5
CVE-2022-40708LOWCVSS 3.3v202022-09-28
CVE-2022-40708 [LOW] CVE-2022-40708: An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker t
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target sy
cvelistv5
CVE-2020-8602HIGHCVSS 7.2v10.0, 11.0, 12.02020-08-27
CVE-2020-8602 [HIGH] CVE-2020-8602: A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vu
A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protection 2.0 SP2 may allow an authenticated attacker with full control privileges to bypass file integrity checks, leading to remote code execution.
cvelistv5nvd
CVE-2020-15601HIGHCVSS 8.1v10.0, 11.0, 12.02020-08-27
CVE-2020-15601 [HIGH] CWE-287 CVE-2020-15601: If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep S
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or
cvelistv5nvd
CVE-2020-8607MEDIUMCVSS 6.7v12.x, 11.x. 10.x2020-08-05
CVE-2020-8607 [MEDIUM] CWE-20 CVE-2020-8607: An input validation vulnerability found in multiple Trend Micro products utilizing a particular vers
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker
cvelistv5nvd
CVE-2019-9488MEDIUMCVSS 4.9v10.xv11.x2019-09-11
CVE-2019-9488 [MEDIUM] CWE-611 CVE-2019-9488: Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to
Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).
cvelistv5nvd