CVE-2025-3599

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 30, 2025
Updated: May 2, 2025
CWE ID 367

Summary

CVE-2025-3599 is a newly identified vulnerability affecting the Symantec Endpoint Protection Windows Agent and its ERASER Engine. This issue grants elevated privileges to attackers, enabling them to delete protected resources from the system. The ERASER Engine, prior to version 119.1.7.8, is the target of the exploit. Successful exploitation could lead to data loss and potential system instability. Users are advised to update their Symantec Endpoint Protection software to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Symantec Endpoint Protection

Affected Vendors

  • Symantec