CVE-2025-13919 - CVE House
Back to Database
Status published Medium CVE-2025-13919

Component Object Model (COM) Hijacking in Symantec Endpoint Protection Windows Client

Vulnerability Description

Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13919

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Gregory DRAPERI

Affected Vendor

Affected Software

Symantec Endpoint Protection Windows Client
Vulnerable Versions:
14.3.12154.10000, 14.3.12167.10000

Timeline

Official Publish: January 28th, 2026
Last Modified: January 30th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Weaknesses (CWE)