CVE-2025-49216

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

08 Sep 2025, 21:10

Type Values Removed Values Added
First Time Microsoft windows
Trendmicro trend Micro Endpoint Encryption
Trendmicro
Microsoft
CPE cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad de omisión de autenticación en Trend Micro Endpoint Encryption PolicyServer podría permitir que un atacante acceda a métodos clave como usuario administrador y modifique las configuraciones del producto en las instalaciones afectadas.
References () https://success.trendmicro.com/en-US/solution/KA-0019928 - () https://success.trendmicro.com/en-US/solution/KA-0019928 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-25-373/ - () https://www.zerodayinitiative.com/advisories/ZDI-25-373/ - Third Party Advisory

17 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 21:15

Updated : 2025-09-08 21:10


NVD link : CVE-2025-49216

Mitre link : CVE-2025-49216

CVE.ORG link : CVE-2025-49216


JSON object : View

Products Affected

microsoft

  • windows

trendmicro

  • trend_micro_endpoint_encryption
CWE
CWE-477

Use of Obsolete Function