An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.
2025-06-17T21:15:38.943
2025-09-08T21:09:04.560
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | trendmicro | trend_micro_endpoint_encryption | < 6.0.0.4013 | Yes |
| Operating System | microsoft | windows | - | No |