Trend Micro Endpoint Encryption PolicyServer SQL Injection Privilege Escalation Vulnerability

Vulnerability

A post-authentication SQL injection vulnerability has been identified in Trend Micro Endpoint Encryption PolicyServer versions prior to 6.0.0.4013. This vulnerability allows an attacker to escalate privileges on affected installations. The issue arises from improper validation of user-supplied input, which can be exploited to manipulate SQL queries and access resources typically restricted from the user. To exploit this vulnerability, an attacker must first gain the ability to execute low-privileged code on the target system.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing attackers to gain access to restricted resources or functionalities within the application.

Remediation

Trend Micro has released a patch for this vulnerability in Endpoint Encryption PolicyServer version 6.0.0.4013. Users are encouraged to update to this version. For more information, visit the Trend Micro Download Center.

Added: Jun 17, 2025, 9:29 PM
Updated: Jun 17, 2025, 9:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.