CVE-2025-58074

Published May 4, 2026

Last updated 4 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-58074 describes a privilege escalation vulnerability found during the installation of Norton Secure VPN when acquired through the Microsoft Store. This flaw allows a user with low privileges to replace files during the installation process. The ability to replace files during installation could lead to the deletion of arbitrary files, which in turn may result in an elevation of privileges for the low-privilege user.

Description
A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.
Source
talos-cna@cisco.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
6
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

talos-cna@cisco.com
CWE-1386

Social media

Hype score
Not currently trending