Database/Firmware, BMC & network fabric

Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot): A signed pre-boot component that allows Secure
Impact
A signed pre-boot component that allows Secure Boot bypass on affected machines. Relevant to any fleet where an endpoint-security vendor's UEFI component is part of the boot chain - the security product itself becomes the way in.
Who can reach it
Local access to a machine running the affected pre-boot component.
What to do
Vendor product update plus, where the binary is revoked, a dbx update. Worth a general lesson for fleet operators: every third-party signed EFI component you allow into the boot chain is a permanent addition to your Secure Boot attack surface, and you cannot remove it later without a revocation rollout.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.