PT-2025-25265 · Trend Micro · Trend Micro Endpoint Encryption
Chudypb
+1
·
Published
2024-10-11
·
Updated
2025-09-08
·
CVE-2025-49212
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Endpoint Encryption versions prior to 6.0.0.4013
Description
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. The issue is related to the deserialization of untrusted data, which can be exploited to execute code remotely without authentication. This vulnerability is actively being exploited.
Recommendations
To resolve the issue, update Trend Micro Endpoint Encryption to version 6.0.0.4013 or later. As a temporary workaround, consider restricting access to the PolicyServer to minimize the risk of exploitation. Avoid using the
DeserializeFromBase64String method in the affected PolicyServer until the issue is resolved.Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Endpoint Encryption