CVE-2025-49216

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

08 Sep 2025, 21:10

Type Values Removed Values Added
First Time Microsoft
Microsoft windows
Trendmicro
Trendmicro trend Micro Endpoint Encryption
Summary
  • (es) Una vulnerabilidad de omisión de autenticación en Trend Micro Endpoint Encryption PolicyServer podría permitir que un atacante acceda a métodos clave como usuario administrador y modifique las configuraciones del producto en las instalaciones afectadas.
References () https://success.trendmicro.com/en-US/solution/KA-0019928 - () https://success.trendmicro.com/en-US/solution/KA-0019928 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-25-373/ - () https://www.zerodayinitiative.com/advisories/ZDI-25-373/ - Third Party Advisory
CPE cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

17 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 21:15

Updated : 2025-09-08 21:10


NVD link : CVE-2025-49216

Mitre link : CVE-2025-49216

CVE.ORG link : CVE-2025-49216


JSON object : View

Products Affected

trendmicro

  • trend_micro_endpoint_encryption

microsoft

  • windows
CWE
CWE-477

Use of Obsolete Function