SQL Injection Vulnerability in Trend Micro Endpoint Encryption PolicyServer
CVE-2025-49211
7.7HIGH
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 17 June 2025
What is CVE-2025-49211?
A SQL injection vulnerability in Trend Micro Endpoint Encryption PolicyServer can permit an attacker to escalate privileges on vulnerable installations. To successfully exploit this vulnerability, the attacker must first execute low-privileged code on the target system, making initial access a critical factor in executing the attack. This vulnerability underscores the importance of securing code execution permissions and monitoring system behaviors to identify potential misuse.
Affected Version(s)
Trend Micro Endpoint Encryption Policy Server 6.0 < 6.0.0.4013
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved