Authentication Bypass in Trend Micro Endpoint Encryption PolicyServer
CVE-2025-49216

9.8CRITICAL

What is CVE-2025-49216?

An authentication bypass vulnerability discovered in Trend Micro Endpoint Encryption PolicyServer exposes a significant risk wherein attackers can gain unauthorized access to critical administrative functionalities. This allows them to manipulate product settings and configurations, potentially leading to broader system compromises on affected installations. Organizations using this software must assess their security measures and apply necessary updates to mitigate risks.

Affected Version(s)

Trend Micro Endpoint Encryption Policy Server 6.0 < 6.0.0.4013

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49216 : Authentication Bypass in Trend Micro Endpoint Encryption PolicyServer