CVE-2025-49216
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.54%
- CWE
- CWE-477
- Published
- 2025-06-17
- Last modified
- 2026-03-13
Affected products
- Trend Micro, Inc. Trend Micro Endpoint Encryption Policy Server
Weakness type
Related vulnerabilities
- CVE-2026-1693 — Use of vulnerable Resource Owner Password Credentials flow
- CVE-2025-49217 — An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could...
- CVE-2025-49214 — An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could...
- CVE-2025-49213 — An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could...
- CVE-2025-49212 — An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could...
- CVE-2025-49220 — An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead...
- CVE-2025-49219 — An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could...
- CVE-2023-28829 — A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC...