CVE-2025-3599: Broadcom Symantec Eraser Engine

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.

Affected products

  • Broadcom Symantec Eraser Engine: before 119.1.7.8 (fixed in 119.1.7.8)

Published 2025-04-30. Last modified 2026-06-17.