CVE-2025-58074Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1386

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-04); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-04: 3Mentions · 2026-05-24: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-05-04: 3Technical Details · 2026-05-24: 105-0405-24
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-043
Disclosure3
2026-05-241
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2025-58074 (CVSS 8.8) Privilege escalation flaw in Norton Secure VPN Microsoft Store installation. Low-priv users can replace files during install, leading to arbitrary file deletion & privilege elevation. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/Hi5csX1Z2U

    Post summary

    A high‑severity privilege escalation flaw (CVE‑2025‑58074) in Norton Secure VPN is highlighted, with a clear recommendation to apply a patch immediately.

    00000471
    30 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-58074 A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the in… https://www.cve.org/CVERecord?id=CVE-2025-58074 ----- Traducción: CVE-2025-58074 Exi… http://infoflow.cloud`

    Post summary

    An announcement of CVE-2025-58074, a privilege escalation flaw in Norton Secure VPN’s Microsoft Store installer, with no PoC, exploit, or patch details provided.

    00000912
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-58074 A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the in… https://www.cve.org/CVERecord?id=CVE-2025-58074

    Post summary

    A privilege escalation vulnerability (CVE-2025-58074) exists during the installation of Norton Secure VPN via the Microsoft Store, allowing low-privilege users to replace files.

    00000577
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-58074 Privilege Escalation via File Replacement in Norton Secure VPN Microsoft Store Installation https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-58074

    Post summary

    The text announces CVE‑2025‑58074, describing a privilege escalation flaw in Norton Secure VPN’s Microsoft Store installation that permits file replacement to gain elevated rights.

    00000491
    4.0K followersView on X

Explore more