Threats Tagged 'cve-2025-13919'
View all threats tagged with 'cve-2025-13919'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-13919'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-13919 is a medium severity vulnerability affecting Broadcom's Symantec Endpoint Protection Windows Client prior to versions 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3. It involves an uncontrolled search path element (CWE-427) that allows an attacker with limited privileges to hijack COM references in the Windows Registry. This hijacking can enable persistence and evasion of detection by redirecting legitimate COM object calls to malicious payloads. The vulnerability requires local access with low privileges and does not require user interaction. Although no known exploits are currently in the wild, the vulnerability impacts the integrity and availability of affected systems. European organizations relying on Symantec Endpoint Protection for endpoint security should prioritize patching to mitigate risks. Countries with significant deployments of Broadcom security products and critical infrastructure are more likely to be targeted. Mitigation involves applying vendor patches, auditing COM registry entries, and enforcing strict access controls on registry keys related to COM objects. Join the discussion | CVE Database V5 | 01/28/2026, 16:41:02 UTC Added: 01/28/2026, 17:05:58 UTC |
Showing 1 to 1 of 1 result