CVE-2025-58074CWE-1386

Privilege escalation during the installation of Norton Secure VPN via the Microsoft Store

High · published May 4, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
3.6
In the wild
Unconfirmed
What it is

A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00139 · 3.6th percentile
Weakness
CWE-1386 · Insecure Operation on Windows Junction / Mount Point
Published
2026-05-04T13:11Z
EPSS history
Timeline
  • 04 MAY 13:11Z
    Privilege escalation during the installation of Norton Secure VPN via the Microsoft Store
    cvelistv5