CVE-2025-49216

CRITICAL

Trend Micro Endpoint Encryption < 6.0.0.4013 - Authentication Bypass

Title source: llm
STIX 2.1

Description

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0024
EPSS Percentile 46.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-477
Status published
Products (1)
trendmicro/trend_micro_endpoint_encryption < 6.0.0.4013
Published Jun 17, 2025
Tracked Since Feb 18, 2026