CVE-2025-30642 Details
Description
A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
A link following vulnerability has been identified in Trend Micro Deep Security Agent version 20.0 prior to 20.0.1-25770 on Windows. This vulnerability allows local attackers to create a denial-of-service condition on affected installations. Exploitation requires the ability to execute low-privileged code on the target system.
Users are advised to update to Trend Micro Deep Security Agent version 20.0.1-25770, available now. For more information, consult the Trend Micro Business Success Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://success.trendmicro.com/en-US/solution/KA-0019344 | [email protected] | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-25-241/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| trendmicro deep security agent | < 20.0.1 20.0.1 - 20.0.1 update12510 20.0.1 update14610 20.0.1 update17380 20.0.1 update19250 20.0.1 update21510 20.0.1 update23340 20.0.1 update3180 20.0.1 update4540 20.0.1 update690 20.0.1 update7380 20.0.1 update9400 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2025 | Initial Analysis | [email protected] |
| Jun 17, 2025 | New CVE Received | [email protected] |