CVE-2025-13917
7.0Broadcom · Symantec Web Security Services Agent
Broadcom Symantec Web Security Services Agent prior to 9.8.5 is susceptible to an improper privilege management vulnerability that could allow for local elevation of privilege.
Executive summary
Broadcom Symantec Web Security Services Agent versions prior to 9.8.5 contain a privilege management vulnerability that permits local attackers to gain unauthorized elevated access.
Vulnerability
This vulnerability is classified as improper privilege management (CWE-269), where a local authenticated user may exploit the application to gain elevated access to protected resources. The attack requires local access and specific conditions (AV:L/AC:H), meaning it is not remotely exploitable over the network.
Business impact
The potential for elevation of privilege poses a significant risk to endpoint security, as a successful exploit could allow a standard user to bypass security controls and perform actions with elevated permissions. Given the CVSS score of 7.0, this is classified as a high-severity issue, as it could facilitate further system compromise or data exfiltration from an already accessed workstation.
Remediation
Immediate Action: Upgrade the Symantec Web Security Services Agent to version 9.8.5 or later to resolve the underlying privilege management flaw.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected administrative actions originating from standard user accounts.
Compensating Controls: Implement strict endpoint access controls and ensure that the principle of least privilege is enforced for all local users to minimize the potential impact of local privilege escalation.
Exploitation status
Public Exploit Available: No
Analyst recommendation
While the attack vector is local and requires elevated complexity, the ability to achieve privilege escalation warrants prompt attention. Organizations should prioritize updating the Symantec Web Security Services Agent to version 9.8.5 across all managed endpoints to ensure the security of the local environment.
More Broadcom CVEs
Sources
Originally found and disclosed by dfc3d21780 Cparta Cyber Defense AB, per the CVE Program record.