CVE-2025-49217 Information

Description

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.

Reference

https://success.trendmicro.com/en-US/solution/KA-0019928 https://www.zerodayinitiative.com/advisories/ZDI-25-374/

CNNVD-202506-2120 (Published: 2025-06-17)

Share on: