COM Hijacking Vulnerability in Symantec Endpoint Protection by Broadcom
CVE-2025-13919
4.4MEDIUM
Key Information:
- Vendor
Broadcom
- Vendor
- CVE Published:
- 28 January 2026
What is CVE-2025-13919?
The vulnerability allows attackers to potentially establish persistence and evade detection by manipulating COM references within the Windows Registry. This can compromise the security integrity of affected systems running earlier versions of Symantec Endpoint Protection. It is crucial for users to update their software to the latest patches to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Symantec Endpoint Protection Windows Client 14.3.12154.10000
Symantec Endpoint Protection Windows Client 14.3.12167.10000
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gregory DRAPERI