PatchDay Alert

CVE

CVE-2025-58074

0field notes · 1digest CVSS 8.8


Daily digests

During installation of Norton Secure VPN from the Microsoft Store, a low-privilege local user can swap out files in the install path. That lets them delete arbitrary files and escalate to higher privileges. This requires local access and the timing window of an active installation, so it's not remotely exploitable, but any shared workstation where Norton Secure VPN gets deployed is at risk.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.