CVE-2025-3599

Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:broadcom:symantec_eraser_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:symantec_endpoint_protection:-:*:*:*:*:windows:*:*

History

21 Aug 2025, 17:32

Type Values Removed Values Added
First Time Broadcom symantec Eraser Engine
CPE cpe:2.3:a:broadcom:symantec_endpoint_protection:*:*:*:*:*:windows:*:* cpe:2.3:a:broadcom:symantec_endpoint_protection:-:*:*:*:*:windows:*:*
cpe:2.3:a:broadcom:symantec_eraser_engine:*:*:*:*:*:*:*:*

16 May 2025, 16:10

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-30 17:15

Updated : 2025-08-21 17:32


NVD link : CVE-2025-3599

Mitre link : CVE-2025-3599

CVE.ORG link : CVE-2025-3599


JSON object : View

Products Affected

broadcom

  • symantec_endpoint_protection
  • symantec_eraser_engine
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

NVD-CWE-noinfo