CVE-2025-58074
Privilege Escalation in Norton Secure VPN via Microsoft Store
Publication date: 2026-05-04
Last updated on: 2026-05-04
Assigner: Talos
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| symantec | norton_secure_vpn | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1386 | The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a privilege escalation issue that occurs during the installation of Norton Secure VPN via the Microsoft Store. Specifically, a user with low privileges can replace files during the installation process.
By doing so, the attacker may cause deletion of arbitrary files, which can ultimately lead to an elevation of privileges on the affected system.
How can this vulnerability impact me? :
This vulnerability can allow a low-privilege user to gain higher privileges on the system by exploiting the installation process of Norton Secure VPN.
Such an elevation of privileges can lead to unauthorized access, modification, or deletion of critical system files, potentially compromising system integrity, confidentiality, and availability.