CVE-2025-58074
Awaiting Analysis Awaiting Analysis - Queue
Privilege Escalation in Norton Secure VPN via Microsoft Store

Publication date: 2026-05-04

Last updated on: 2026-05-04

Assigner: Talos

Description
A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-04
Last Modified
2026-05-04
Generated
2026-05-07
AI Q&A
2026-05-05
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
symantec norton_secure_vpn *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1386 The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a privilege escalation issue that occurs during the installation of Norton Secure VPN via the Microsoft Store. Specifically, a user with low privileges can replace files during the installation process.

By doing so, the attacker may cause deletion of arbitrary files, which can ultimately lead to an elevation of privileges on the affected system.


How can this vulnerability impact me? :

This vulnerability can allow a low-privilege user to gain higher privileges on the system by exploiting the installation process of Norton Secure VPN.

Such an elevation of privileges can lead to unauthorized access, modification, or deletion of critical system files, potentially compromising system integrity, confidentiality, and availability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart