An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
History

Mon, 08 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Trendmicro trend Micro Endpoint Encryption
CPEs cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows
Trendmicro trend Micro Endpoint Encryption

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00051}

epss

{'score': 0.00067}


Wed, 18 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 20:45:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
First Time appeared Trendmicro
Trendmicro endpoint Encryption Policy Server
Weaknesses CWE-477
CPEs cpe:2.3:a:trendmicro:endpoint_encryption_policy_server:6.0.0.4013:p1u6:*:*:*:*:*:*
Vendors & Products Trendmicro
Trendmicro endpoint Encryption Policy Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: trendmicro

Published: 2025-06-17T20:28:07.764Z

Updated: 2025-06-18T14:05:54.493Z

Reserved: 2025-06-03T18:11:27.259Z

Link: CVE-2025-49216

cve-icon Vulnrichment

Updated: 2025-06-18T14:04:08.262Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-17T21:15:39.437

Modified: 2025-09-08T21:10:36.310

Link: CVE-2025-49216

cve-icon Redhat

No data.