CVE-2025-3599: Symantec Endpoint Protection Elevation of Privilege

6.5 CVSS

Description

Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.

Classification

CVE ID: CVE-2025-3599

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Problem Types

CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

Affected Products

Vendor: Symantec

Product: Symantec Endpoint Protection

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.77% (scored less or equal to compared to others)

EPSS Date: 2025-05-07 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-3599
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25659

Timeline