# CVE-2025-49216

## Summary

- **CVE ID:** CVE-2025-49216
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-477
- **Published:** Jun 17, 2025
- **Last Modified:** Mar 13, 2026

## Description

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

## Affected Products

- Trend Micro, Inc. — Trend Micro Endpoint Encryption Policy Server (6.0)

## References

- [CNA](https://success.trendmicro.com/en-US/solution/KA-0019928)
- [CNA](https://www.zerodayinitiative.com/advisories/ZDI-25-373/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.54%
- **EPSS Percentile:** 43.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._