A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.
History

Fri, 29 May 2026 13:45:00 +0000


Thu, 28 May 2026 17:30:00 +0000

Type Values Removed Values Added
References

Thu, 28 May 2026 17:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation During Norton Secure VPN Installation via Microsoft Store Privilege escalation during the installation of Norton Secure VPN via the Microsoft Store
References

Mon, 04 May 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Gen Digital
Gen Digital norton Secure Vpn
Vendors & Products Gen Digital
Gen Digital norton Secure Vpn

Mon, 04 May 2026 15:30:00 +0000


Mon, 04 May 2026 15:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation During Norton Secure VPN Installation via Microsoft Store

Mon, 04 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 04 May 2026 13:30:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.
Weaknesses CWE-1386
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published: 2026-05-04T13:11:08.628Z

Updated: 2026-05-29T13:35:53.911Z

Reserved: 2025-09-19T13:36:50.208Z

Link: CVE-2025-58074

cve-icon Vulnrichment

Updated: 2026-05-04T14:44:32.529Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-04T14:16:28.480

Modified: 2026-05-29T14:16:24.667

Link: CVE-2025-58074

cve-icon Redhat

No data.