A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate to full privileges within the target AWS account.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HTrendmicro Deep Security As A Service
APPTrendmicroall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
Related vulnerabilities
CVE-2025-54948CRITICAL9.4⚠ KEVPL ✓same vendor
Command injection w Trend Micro Apex One – RCE bez uwierzytelnienia
CVE-2022-26871CRITICAL9.8⚠ KEVPL ✓same vendor
Trend Micro Apex Central — dowolne przesyłanie plików prowadzące do RCE
CVE-2020-8599CRITICAL9.8⚠ KEVPL ✓same vendor
Trend Micro Apex One / OfficeScan XG — zapis pliku bez uwierzytelnienia i bypass loginu ROOT
CVE-2025-69258CRITICAL9.8PL ✓same vendor
Krytyczna podatność LoadLibraryEX w Trend Micro Apex Central — RCE jako SYSTEM
CVE-2025-54987CRITICAL9.4PL ✓same vendor
RCE w Trend Micro Apex One – command injection bez uwierzytelnienia