An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.
| Software | From | Fixed in |
|---|---|---|
| trendmicro / apex_central | 2019 | 2019.x |
| trendmicro / apex_central | 2019-build_3752 | 2019-build_3752.x |
| trendmicro / apex_central | 2019-build_5158 | 2019-build_5158.x |
| trendmicro / apex_central | 2019-build_6016 | 2019-build_6016.x |
| trendmicro / apex_central | 2019-build_6288 | 2019-build_6288.x |
| trendmicro / apex_central | 2019-build_6394 | 2019-build_6394.x |
| trendmicro / apex_central | 2019-build_6481 | 2019-build_6481.x |
| trendmicro / apex_central | 2019-build_6511 | 2019-build_6511.x |
| trendmicro / apex_central | 2019-build_6571 | 2019-build_6571.x |
| trendmicro / apex_central | 2019-build_6658 | 2019-build_6658.x |
| trendmicro / apex_central | 2019-build_6660 | 2019-build_6660.x |
| trendmicro / apex_central | 2019-build_6890 | 2019-build_6890.x |
| trendmicro / apex_central | 2019-build_6955 | 2019-build_6955.x |