CVE-2025-58074
8.8 HIGHA privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store
Published: 2026-05-04 · Last updated: 2026-05-29
Severity and scoring
- CVSS
- 8.8 HIGH
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE
- CWE-1386
Description
A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.
Source: NVD
References
Related CVEs
Same CWE
- CVE-2026-41116 — Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vuln... (6.3 MEDIUM)