SQL Injection Vulnerability in Trend Micro Endpoint Encryption PolicyServer
CVE-2025-49211

7.7HIGH

What is CVE-2025-49211?

A SQL injection vulnerability in Trend Micro Endpoint Encryption PolicyServer can permit an attacker to escalate privileges on vulnerable installations. To successfully exploit this vulnerability, the attacker must first execute low-privileged code on the target system, making initial access a critical factor in executing the attack. This vulnerability underscores the importance of securing code execution permissions and monitoring system behaviors to identify potential misuse.

Affected Version(s)

Trend Micro Endpoint Encryption Policy Server 6.0 < 6.0.0.4013

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49211 : SQL Injection Vulnerability in Trend Micro Endpoint Encryption PolicyServer