CVE-2025-13918 Details
Description
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
A vulnerability allowing elevation of privilege has been identified in Symantec Endpoint Protection (SEP) Windows client, affecting versions prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3. This vulnerability allows an attacker to gain elevated access to resources typically protected from users or applications.
Users can upgrade to Symantec Endpoint Protection 14.3 RU10 (14.3.12167.10000), 14.3 RU9 (14.3.11237.9000), or 14.3 RU8 (14.3.10178.8000). The latest releases and patches are available through normal support channels. Versions 14.3 RU10 and 14.3 RU9 can be obtained via Symantec LiveUpdate for Cloud-Managed and On-Premise customers. The 14.3 RU8 update is available through LiveUpdate to the Symantec Endpoint Protection Manager.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 28, 2026CISA-ADP
Assessed Jan 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36774 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Symantec Endpoint Protection | < 14.3 RU10 Patch 1 < 14.3 RU9 Patch 2 < 14.3 RU8 Patch 3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 28, 2026 | New CVE Received | [email protected] |
Volerion