CVE-2025-3599: Symantec Endpoint Protection Elevation of Privilege
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3599?
CVE-2025-3599 is classified as an Elevation of Privilege vulnerability, which can potentially allow unauthorized deletion of protected resources.
How do I fix CVE-2025-3599?
To mitigate CVE-2025-3599, update the Symantec Endpoint Protection Windows Agent to version 119.1.7.8 or later.
Who is affected by CVE-2025-3599?
CVE-2025-3599 affects users of the Symantec Endpoint Protection Windows Agent running versions prior to 119.1.7.8.
What can an attacker do using CVE-2025-3599?
An attacker exploiting CVE-2025-3599 can delete resources that are typically safeguarded against unauthorized access.
Is there a workaround for CVE-2025-3599?
While upgrading to the latest version is the recommended solution, temporarily restricting access to vulnerable components may serve as a workaround.