CVE-2025-49218

A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

08 Sep 2025, 21:13

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección SQL posterior a la autenticación en Trend Micro Endpoint Encryption PolicyServer podría permitir a un atacante escalar privilegios en las instalaciones afectadas. Esto es similar, pero no idéntico, a CVE-2025-49215. Nota: Para explotar esta vulnerabilidad, un atacante primero debe poder ejecutar código con pocos privilegios en el sistema objetivo.
First Time Microsoft windows
Trendmicro trend Micro Endpoint Encryption
Trendmicro
Microsoft
CPE cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://success.trendmicro.com/en-US/solution/KA-0019928 - () https://success.trendmicro.com/en-US/solution/KA-0019928 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-25-375/ - () https://www.zerodayinitiative.com/advisories/ZDI-25-375/ - Third Party Advisory

17 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 21:15

Updated : 2025-09-08 21:13


NVD link : CVE-2025-49218

Mitre link : CVE-2025-49218

CVE.ORG link : CVE-2025-49218


JSON object : View

Products Affected

microsoft

  • windows

trendmicro

  • trend_micro_endpoint_encryption
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')