← All CVEs

CVE-2025-49216

critical · 9.8

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

9.8
CVSS
0.5%
EPSS (exploit prob.)
45th
EPSS percentile
2025-06-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-477

Affected products

VendorProductAffected versions
trendmicrotrend_micro_endpoint_encryption< 6.0.0.4013
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-49216