← Back to browse · API

CVE-2025-49212

Severity
CRITICAL
CVSS
9.8
EPSS
0.09845
Risk score
42.65
CISA KEV
No
PoC
No
Published
2025-06-17
Modified
2025-06-18
First seen
2026-08-07
Aliases
EUVD-2025-18640, GHSA-MP4Q-GCM4-WW9C
Products
Trend Micro, Inc.:Trend Micro Endpoint Encryption Policy Server 6.0 <6.0.0.4013
Sources
euvd EUVD-2025-18640

Description

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.

References