CVE-2025-49216 PUBLISHED

Assigner: trendmicro
Reserved: 03.06.2025 Published: 17.06.2025 Updated: 18.06.2025

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Trend Micro, Inc.
Product Trend Micro Endpoint Encryption Policy Server
Versions
  • affected from 6.0 to 6.0.0.4013 (excl.)

References

Problem Types