Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-0893 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-269Improper Privilege ManagementCISA-ADP

Affected Products

ProductVersions
Symantec Diagnostic Tool
< 3.0.79 (semver)

CPE

  • cpe:2.3:a:symantec:symdiag:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 3.0.79moderate effort
  • Mitigation:low effort

    Restrict access to administrative or management systems to authorized privileged users.

  • Mitigation:low effort

    Restrict remote access to trusted/authorized systems only.

  • Mitigation:low effort

    Run under the principle of least privilege, where possible, to limit the impact of potential exploit.

  • Mitigation:low effort

    Keep all operating systems and applications current with vendor patches.

  • Mitigation:low effort

    Follow a multi-layered approach to security. At a minimum, run both firewall and anti-malware applications to provide multiple points of detection and protection for both inbound and outbound threats.

  • Mitigation:low effort

    Deploy network and host-based intrusion detection systems to monitor network traffic for signs of anomalous or suspicious activity. This may aid in the detection of attacks or malicious activity related to the exploitation of latent vulnerabilities.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-0893
NVD Published Date:
Feb 19, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-0893 Details - Not Deferred