Trendmicro Trend Micro Endpoint Encryption vulnerabilities
9 known vulnerabilities affecting trendmicro/trend_micro_endpoint_encryption.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH4MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-49217CRITICALCVSS 9.8fixed in 6.0.0.40132025-06-17
CVE-2025-49217 [CRITICAL] CVE-2025-49217: An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.
nvd
CVE-2025-49213CRITICALCVSS 9.8fixed in 6.0.0.40132025-06-17
CVE-2025-49213 [CRITICAL] CWE-477 CVE-2025-49213: An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.
nvd
CVE-2025-49212CRITICALCVSS 9.8fixed in 6.0.0.40132025-06-17
CVE-2025-49212 [CRITICAL] CWE-477 CVE-2025-49212: An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.
nvd
CVE-2025-49216CRITICALCVSS 9.8fixed in 6.0.0.40132025-06-17
CVE-2025-49216 [CRITICAL] CWE-477 CVE-2025-49216: An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could all
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
nvd
CVE-2025-49211HIGHCVSS 7.8fixed in 6.0.0.40132025-06-17
CVE-2025-49211 [HIGH] CWE-89 CVE-2025-49211: A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an att
A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
nvd
CVE-2025-49218HIGHCVSS 7.8fixed in 6.0.0.40132025-06-17
CVE-2025-49218 [HIGH] CVE-2025-49218: A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could al
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
nvd
CVE-2025-49215HIGHCVSS 8.8fixed in 6.0.0.40132025-06-17
CVE-2025-49215 [HIGH] CWE-242 CVE-2025-49215: A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could al
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
nvd
CVE-2025-49214HIGHCVSS 8.8fixed in 6.0.0.40132025-06-17
CVE-2025-49214 [HIGH] CWE-477 CVE-2025-49214: An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
nvd
CVE-2023-28005MEDIUMCVSS 6.8≤ 6.0.0.32042023-03-22
CVE-2023-28005 [MEDIUM] CVE-2023-28005: A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below
A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to obtain access to the contents of the device.
An attacker must first obtain physical access to the t
nvd