CVE-2025-13919Patch

LOWCVSS 4.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-01-28)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-27: 1Mentions · 2026-01-28: 2Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-28: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 101-2701-28
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-271
Patch1
2026-01-282
Disclosure1Patch1
Full discourse3 posts
  • Autumn Good@autumn_good_35
    Patch

    SEPで権限昇格とCOMハイジャックの脆弱性 CVE-2025-13918 CVE-2025-13919 Symantec Endpoint Protection Security Update https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36774

    Post summary

    Symantec Endpoint Protection (SEP) is affected by CVE-2025-13918 and CVE-2025-13919, which enable privilege escalation and COM hijacking; a security update is available to remediate the issues.

    00010409
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-13919 COM Hijacking Vulnerability in Symantec Endpoint Protection Before 14.3 ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-13919 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces a newly disclosed vulnerability (CVE‑2025‑13919) in Symantec Endpoint Protection but does not provide technical details, proof of concept, exploit code, or active exploitation claims.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-13919 Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue … https://www.cve.org/CVERecord?id=CVE-2025-13919

    Post summary

    CVE-2025-13919 is linked to a COM Hijacking vulnerability in older Symantec Endpoint Protection releases; patches 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3 are referenced as mitigation measures.

    00000124
    56.5K followersView on X

Explore more