CVE-2025-13919: Component Object Model (COM) Hijacking in Symantec Endpoint Protection Windows Client
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13919?
CVE-2025-13919 has a moderate severity rating due to its potential impact on system security through COM Hijacking.
How do I fix CVE-2025-13919?
To fix CVE-2025-13919, update Symantec Endpoint Protection to version 14.3 RU10 Patch 1 or later.
What is COM Hijacking in the context of CVE-2025-13919?
COM Hijacking in CVE-2025-13919 refers to a vulnerability where an attacker can manipulate COM objects to execute arbitrary code.
Which versions of Symantec Endpoint Protection are affected by CVE-2025-13919?
CVE-2025-13919 affects versions of Symantec Endpoint Protection prior to 14.3 RU10 Patch 1.
Is there a workaround for CVE-2025-13919 if I can't update Symantec Endpoint Protection?
There are no documented workarounds for CVE-2025-13919, so the recommended action is to apply the available updates.