An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method.
2025-06-17T18:15:27.033
2025-09-08T21:06:21.787
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Application | trendmicro | apex_central | 2019 | Yes |
| Operating System | microsoft | windows | - | No |