An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
References
Link | Resource |
---|---|
https://success.trendmicro.com/en-US/solution/KA-0019928 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-25-373/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
08 Sep 2025, 21:10
Type | Values Removed | Values Added |
---|---|---|
First Time |
Microsoft windows
Trendmicro trend Micro Endpoint Encryption Trendmicro Microsoft |
|
CPE | cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Summary |
|
|
References | () https://success.trendmicro.com/en-US/solution/KA-0019928 - Vendor Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-25-373/ - Third Party Advisory |
17 Jun 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-17 21:15
Updated : 2025-09-08 21:10
NVD link : CVE-2025-49216
Mitre link : CVE-2025-49216
CVE.ORG link : CVE-2025-49216
JSON object : View
Products Affected
microsoft
- windows
trendmicro
- trend_micro_endpoint_encryption
CWE
CWE-477
Use of Obsolete Function