A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Trendmicro trend Micro Endpoint Encryption |
|
| CPEs | cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows Trendmicro trend Micro Endpoint Encryption |
Fri, 20 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Jun 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| First Time appeared |
Trendmicro
Trendmicro endpoint Encryption Policy Server |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:trendmicro:endpoint_encryption_policy_server:6.0.0.4013:p1u6:*:*:*:*:*:* | |
| Vendors & Products |
Trendmicro
Trendmicro endpoint Encryption Policy Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: trendmicro
Published: 2025-06-17T20:16:38.307Z
Updated: 2025-06-20T13:12:22.833Z
Reserved: 2025-06-03T18:11:27.258Z
Link: CVE-2025-49211
Updated: 2025-06-18T14:19:46.547Z
Status : Analyzed
Published: 2025-06-17T21:15:38.827
Modified: 2025-09-08T21:08:51.120
Link: CVE-2025-49211
No data.