Privilege Escalation in Norton Secure VPN by NortonLifeLock
CVE-2025-58074

8.8HIGH

Key Information:

Vendor
CVE Published:
4 May 2026

What is CVE-2025-58074?

A privilege escalation vulnerability allows low-privilege users to exploit the Norton Secure VPN installation process via the Microsoft Store. During installation, these users can tamper with files, potentially leading to the deletion of arbitrary system files. This could ultimately allow the attacker to gain elevated privileges, compromising system integrity and potentially exposing sensitive data.

Affected Version(s)

Norton Secure VPN 6.5.0.59

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by KPC of Cisco Talos.
.