Vulnerability Description
An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Apex Central | 2019 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://success.trendmicro.com/en-US/solution/KA-0019926Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-25-367/Third Party Advisory
FAQ
What is CVE-2025-49220?
CVE-2025-49220 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerabilit...
How severe is CVE-2025-49220?
CVE-2025-49220 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-49220?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Apex Central, Microsoft Windows.