CVE-2025-3599

Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:broadcom:symantec_endpoint_protection:*:*:*:*:*:windows:*:*

History

16 May 2025, 16:10

Type Values Removed Values Added
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25659 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25659 - Vendor Advisory
First Time Broadcom
Broadcom symantec Endpoint Protection
CPE cpe:2.3:a:broadcom:symantec_endpoint_protection:*:*:*:*:*:windows:*:*
CWE NVD-CWE-noinfo

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) Symantec Endpoint Protection Windows Agent, que ejecuta un motor ERASER anterior a 119.1.7.8, puede ser susceptible a una vulnerabilidad de elevación de privilegios, que puede permitir a un atacante eliminar recursos que normalmente están protegidos de una aplicación o un usuario.

30 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-30 17:15

Updated : 2025-05-16 16:10


NVD link : CVE-2025-3599

Mitre link : CVE-2025-3599

CVE.ORG link : CVE-2025-3599


JSON object : View

Products Affected

broadcom

  • symantec_endpoint_protection
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

NVD-CWE-noinfo