Cyber Resilience

CVE-2023-28005

Trendmicro Trend Micro Endpoint Encryption ≤ 6.0.0.3204

Published
22 March 2023
Modified
05 May 2025
Patch / advisory
CVSS Score v3.1 6.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0020 10th percentile
Risk Priority 48 floored blend · peak EPSS

Summary

CVE-2023-28005 is a medium-severity an unspecified weakness vulnerability in Trendmicro Trend Micro Endpoint Encryption. Its CVSS base score is 6.8 (Medium).

Operationally, ranked at the 10th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to…

more

obtain access to the contents of the device. An attacker must first obtain physical access to the target system in order to exploit this vulnerability. It is also important to note that the contents of the drive(s) encrypted with TMEE FDE would still be protected and would NOT be accessible by the attacker by exploitation of this vulnerability alone.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-49212Same product: Microsoft Windows
CVE-2025-49215Same product: Microsoft Windows
CVE-2025-49214Same product: Microsoft Windows
CVE-2025-49213Same product: Microsoft Windows
CVE-2025-49211Same product: Microsoft Windows
CVE-2025-49218Same product: Microsoft Windows
CVE-2025-49216Same product: Microsoft Windows
CVE-2025-49217Same product: Microsoft Windows
CVE-2025-47865Same product: Microsoft Windows
CVE-2023-30902Same product: Microsoft Windows

Affected Assets

trendmicro
trend micro endpoint encryption
≤ 6.0.0.3204

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References