PT-2025-25266 · Trend Micro · Trend Micro Endpoint Encryption

Chudypb

+1

·

Published

2024-10-11

·

Updated

2025-09-08

·

CVE-2025-49213

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Endpoint Encryption (TMEE) (affected versions not specified)
Description The issue is related to insufficient input validation in the PolicyServerWindowsService class of the Trend Micro Endpoint Encryption (TMEE) PolicyServer data encryption tool. This can be exploited by a remote attacker to execute arbitrary code. The vulnerability involves deserialization of untrusted data, which can lead to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-06795
CVE-2025-49213
ZDI-25-370

Affected Products

Trend Micro Endpoint Encryption