PT-2025-25271 · Trend Micro · Trend Micro Apex Central

Published

2024-11-13

·

Updated

2025-09-08

·

CVE-2025-49219

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro Apex Central versions prior to 8.0.7007
Description The issue is related to an insecure deserialization operation in Trend Micro Apex Central, which could lead to a pre-authentication remote code execution on affected installations.
Recommendations For versions prior to 8.0.7007, update to version 8.0.7007 or later to resolve the issue. As a temporary workaround, consider restricting access to the GetReportDetailView function until a patch is available.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-08896
CVE-2025-49219
ZDI-25-366

Affected Products

Trend Micro Apex Central