CVE-2025-58074
Awaiting Analysis
Awaiting Analysis - Queue
Privilege Escalation in Norton Secure VPN via Microsoft Store
Publication date: 2026-05-04
Last updated on: 2026-05-29
Assigner: Talos
Description
Description
A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| symantec | norton_secure_vpn | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1386 | The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere. |