6.7
CVE-2025-13918
- EPSS 0.01%
- Veröffentlicht 28.01.2026 16:35:43
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle secure@symantec.com
- CVE-Watchlists
- Unerledigt
Elevation of Privileges in Symantec Endpoint Protection Windows Client
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerBroadcom
≫
Produkt
Symantec Endpoint Protection Windows Client
Default Statusunaffected
Version
14.3.12154.10000
Status
affected
Version
14.3.12167.10000
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.003 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@symantec.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.