CVE-2025-49213

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

08 Sep 2025, 21:09

Type Values Removed Values Added
First Time Microsoft windows
Trendmicro trend Micro Endpoint Encryption
Trendmicro
Microsoft
CWE CWE-502
References () https://success.trendmicro.com/en-US/solution/KA-0019928 - () https://success.trendmicro.com/en-US/solution/KA-0019928 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-25-370/ - () https://www.zerodayinitiative.com/advisories/ZDI-25-370/ - Third Party Advisory
CPE cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Summary
  • (es) Una operación de deserialización insegura en Trend Micro Endpoint Encryption PolicyServer podría provocar la ejecución remota de código antes de la autenticación en las instalaciones afectadas. Tenga en cuenta que esta vulnerabilidad es similar a CVE-2025-49212, pero se presenta con un método diferente.

17 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 21:15

Updated : 2025-09-08 21:09


NVD link : CVE-2025-49213

Mitre link : CVE-2025-49213

CVE.ORG link : CVE-2025-49213


JSON object : View

Products Affected

microsoft

  • windows

trendmicro

  • trend_micro_endpoint_encryption
CWE
CWE-477

Use of Obsolete Function

CWE-502

Deserialization of Untrusted Data