An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.
2025-06-17T21:15:39.063
2025-09-08T21:09:21.877
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | trendmicro | trend_micro_endpoint_encryption | < 6.0.0.4013 | Yes |
| Operating System | microsoft | windows | - | No |