{"document":{"category":"csaf_vex","csaf_version":"2.0","notes":[{"category":"summary","text":"CRITICAL SECURITY BULLETIN: Trend Micro Apex Central (June 2025)","title":"Title"}],"publisher":{"category":"vendor","contact_details":"security@trendmicro.com","issuing_authority":"Trend Micro PSIRT","name":"Trend Micro","namespace":"https://www.trendmicro.com/vulnerability"},"references":[{"summary":"Trend Micro Security Bulletin","url":"https://success.trendmicro.com/en-US/solution/KA-0019926"}],"title":"CRITICAL SECURITY BULLETIN: Trend Micro Apex Central (June 2025)","tracking":{"current_release_date":"2025-06-10T10:00:00.000Z","generator":{"date":"2025-07-23T18:30:30.614Z","engine":{"name":"Secvisogram","version":"2.5.31"}},"id":"2025-0610-TM-AC-001","initial_release_date":"2025-06-10T10:00:00.000Z","revision_history":[{"date":"2025-06-10T10:00:00.000Z","number":"1","summary":"Initial version."}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"2019","product":{"name":"Trend Micro Apex Central","product_id":"TM-AC-001"}}],"category":"product_name","name":"Apex Central"}],"category":"vendor","name":"Trend Micro"}]},"vulnerabilities":[{"acknowledgments":[{"names":["Anonymous working with Trend Zero Day Initiative"]}],"cve":"CVE-2025-49219","cwe":{"id":"CWE-477","name":"Use of Obsolete Function"},"notes":[{"category":"description","text":"An insecure deserialization operation in Trend Micro Apex Central could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.","title":"CVE description"}],"product_status":{"known_affected":["TM-AC-001"]},"references":[{"category":"external","summary":"ZDI-CAN-25286","url":"https://www.zerodayinitiative.com/advisories/published/"}],"remediations":[{"category":"vendor_fix","date":"2025-06-18T19:00:00.000Z","details":"Customers should update to Critical Patch B7007 which addresses this issue.","product_ids":["TM-AC-001"],"url":"https://downloadcenter.trendmicro.com/index.php?regs=nabu&prodid=1746"}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.8,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.8,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["TM-AC-001"]}],"title":"Deserialization of Untrusted Data RCE Vulnerability "},{"acknowledgments":[{"names":["Piotr Bazydlo (@chudypb) of Trend Zero Day Initiative"]}],"cve":"CVE-2025-49220","cwe":{"id":"CWE-477","name":"Use of Obsolete Function"},"notes":[{"category":"description","text":"An insecure deserialization operation in Trend Micro Apex Central could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method.","title":"CVE description"}],"product_status":{"known_affected":["TM-AC-001"]},"references":[{"category":"external","summary":"ZDI-CAN-25495","url":"https://www.zerodayinitiative.com/advisories/published/"}],"remediations":[{"category":"vendor_fix","date":"2025-06-18T19:00:00.000Z","details":"Customers should update to Critical Patch B7007 which addresses this issue.","product_ids":["TM-AC-001"],"url":"https://downloadcenter.trendmicro.com/index.php?regs=nabu&prodid=1746"}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.8,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.8,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["TM-AC-001"]}],"title":"Deserialization of Untrusted Data RCE Vulnerability"}]}