CVE-2019-18191

HIGH

Trendmicro Deep Security AS A Service - Privilege Escalation

Title source: rule
STIX 2.1

Description

A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate to full privileges within the target AWS account.

Scores

CVSS v3 8.8
EPSS 0.0076
EPSS Percentile 73.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-459
Status published
Products (1)
trendmicro/deep_security_as_a_service
Published Dec 16, 2019
Tracked Since Feb 18, 2026