CVE-2025-13918Patch

LOWCVSS 6.7 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked at 2 mentions on most recent observed day (2026-01-28)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-27: 1Mentions · 2026-01-28: 2Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-28: 2Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 201-2701-28
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-271
Patch1
2026-01-282
Patch2
Full discourse3 posts
  • Autumn Good@autumn_good_35
    Patch

    SEPで権限昇格とCOMハイジャックの脆弱性 CVE-2025-13918 CVE-2025-13919 Symantec Endpoint Protection Security Update https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36774

    Post summary

    The advisory announces CVE‑2025‑13918 and CVE‑2025‑13919 affect Symantec Endpoint Protection by enabling privilege escalation and COM hijacking, and references a vendor security update. No PoC or exploitation activity is mentioned.

    00010409
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2025-13918 Symantec Endpoint Protection Elevation of Privilege Vulnerability Before 14.3 RU10 Patch 1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-13918

    Post summary

    Symantec Endpoint Protection suffers an elevation‑of‑privilege flaw (CVE‑2025‑13918) that is remedied by applying version 14.3 RU10 Patch 1.

    0000046
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-13918 Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type … https://www.cve.org/CVERecord?id=CVE-2025-13918

    Post summary

    CVE-2025-13918 is a disclosed Elevation of Privilege vulnerability in Symantec Endpoint Protection; patches RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3 are recommended to mitigate the risk.

    00000131
    56.5K followersView on X

Explore more