An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
History

Wed, 18 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 20:45:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
First Time appeared Trendmicro
Trendmicro endpoint Encryption Policy Server
Weaknesses CWE-477
CPEs cpe:2.3:a:trendmicro:endpoint_encryption_policy_server:6.0.0.4013:p1u6:*:*:*:*:*:*
Vendors & Products Trendmicro
Trendmicro endpoint Encryption Policy Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: trendmicro

Published: 2025-06-17T20:28:07.764Z

Updated: 2025-06-18T14:05:54.493Z

Reserved: 2025-06-03T18:11:27.259Z

Link: CVE-2025-49216

cve-icon Vulnrichment

Updated: 2025-06-18T14:04:08.262Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-17T21:15:39.437

Modified: 2025-06-18T13:46:52.973

Link: CVE-2025-49216

cve-icon Redhat

No data.