Vulnerability Description
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Trend Micro Endpoint Encryption | < 6.0.0.4013 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://success.trendmicro.com/en-US/solution/KA-0019928Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-25-369/Third Party Advisory
FAQ
What is CVE-2025-49212?
CVE-2025-49212 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerabili...
How severe is CVE-2025-49212?
CVE-2025-49212 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-49212?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Trend Micro Endpoint Encryption, Microsoft Windows.