Trend Micro Vulnerabilities Fixed | Security Update
- Trend Micro has issued security updates to resolve multiple critical vulnerabilities, including remote code execution (RCE) and authentication bypass issues, in its Apex Central and Endpoint Encryption (TMEE)...
- Endpoint Encryption PolicyServer manages Trend Micro Endpoint Encryption (TMEE), providing full disk and removable media encryption for Windows endpoints.
- The latest Endpoint Encryption PolicyServer update addresses these critical vulnerabilities:
Trend Micro users, take note: Critical remote code execution (RCE) flaws and authentication bypass vulnerabilities have been fixed in Apex Central and Endpoint Encryption. These security updates are crucial, addressing major weaknesses that could leave your systems exposed, as detailed by News Directory 3. The updates tackle pre-authentication RCE and other high-impact issues. specifically,the endpoint Encryption PolicyServer update targets flaws involving insecure deserialization,possibly granting unauthorized access. Apex Central users also need to update immediately. Ensure your systems are protected by applying patch B7007 for Apex Central 2019 (on-premise) or receiving automatic updates for Apex Central as a Service. Discover what’s next to stay ahead of cyber threats.
Trend Micro Patches Critical RCE Flaws in Apex Central, Endpoint Encryption
Updated June 13, 2025
Trend Micro has issued security updates to resolve multiple critical vulnerabilities, including remote code execution (RCE) and authentication bypass issues, in its Apex Central and Endpoint Encryption (TMEE) PolicyServer products. The company reports no evidence of active exploitation but urges users to apply the patches immediately to mitigate potential risks.
Endpoint Encryption PolicyServer manages Trend Micro Endpoint Encryption (TMEE), providing full disk and removable media encryption for Windows endpoints. It is commonly used in enterprise environments within regulated industries where data protection compliance is essential. The update addresses several high-severity and critical flaws, enhancing overall security.
The latest Endpoint Encryption PolicyServer update addresses these critical vulnerabilities:
- CVE-2025-49212: A pre-authentication remote code execution flaw due to insecure deserialization.
- CVE-2025-49213: A pre-authentication remote code execution vulnerability stemming from deserialization of untrusted data.
- CVE-2025-49216: An authentication bypass flaw allowing attackers to perform admin-level actions without credentials.
- CVE-2025-49217: A pre-authentication RCE vulnerability triggered by unsafe deserialization.
Trend Micro’s security bulletin lists all four vulnerabilities as critical, though Zero Day Initiative (ZDI) assessed CVE-2025-49217 as high severity.
Version 6.0.0.4013 (Patch 1 Update 6) addresses all vulnerabilities, impacting all versions up to the latest. No workarounds are available, making patching essential.
Trend Micro also addressed two critical pre-authentication remote code execution flaws affecting Apex Central, a centralized security management console. These flaws are:
- CVE-2025-49219: A pre-authentication RCE flaw in the GetReportDetailView method caused by insecure deserialization.
- CVE-2025-49220: A pre-authentication RCE in the ConvertFromJson method due to improper input validation during deserialization.
Patch B7007 for Apex Central 2019 (on-premise) fixes these issues, while Apex Central as a Service receives automatic updates.
What’s next
Users of Trend Micro apex Central and Endpoint Encryption are strongly advised to apply the latest patches to protect against potential exploitation of these critical vulnerabilities. Regular security updates are crucial for maintaining a robust defense against evolving cyber threats.
