CVE-2025-3599
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 30, 2025
Updated: May 2, 2025
CWE ID 367
Summary
CVE-2025-3599 is a newly identified vulnerability affecting the Symantec Endpoint Protection Windows Agent and its ERASER Engine. This issue grants elevated privileges to attackers, enabling them to delete protected resources from the system. The ERASER Engine, prior to version 119.1.7.8, is the target of the exploit. Successful exploitation could lead to data loss and potential system instability. Users are advised to update their Symantec Endpoint Protection software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Symantec Endpoint Protection
Affected Vendors
- Symantec