CVE-2025-13919: Broadcom Symantec Endpoint Protection Windows Client
Medium severity, CVSS 4.4. EPSS: 0.1% chance of exploitation in the next 30 days.
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry.
Affected products
- Broadcom Symantec Endpoint Protection Windows Client: version 14.3.12154.10000 only
Published 2026-01-28. Last modified 2026-06-17.