A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
The product calls a function that can never be guaranteed to work safely.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Trend_micro_endpoint_encryption | Trendmicro | * | 6.0.0.4013 (excluding) |