Описание
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Ссылки
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Одновременно
EPSS
7.7 High
CVSS3
7.8 High
CVSS3
Дефекты
Связанные уязвимости
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Уязвимость функции ProcessWhereClause сервера PolicyServer средства шифрования данных Trend Micro Endpoint Encryption (TMEE), позволяющая нарушителю повысить свои привилегии
EPSS
7.7 High
CVSS3
7.8 High
CVSS3