CVE-2026-3991
Received
Received - Intake
Elevation of Privilege in Symantec DLP Windows Endpoint
Publication date: 2026-03-30
Last updated on: 2026-03-30
Assigner: Symantec Corporation
Description
Description
Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| symantec | data_loss_prevention | to 25.1 (exc) |
| symantec | data_loss_prevention | to 16.1 (exc) |
| symantec | data_loss_prevention | to 16.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-829 | The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere. |