Symantec DLP Agent Vulnerability Let Attackers Escalate Privileges
ID: 53078701-4ee3-58a1-ab64-ac0f12b24c19
STIX ID: report--53078701-4ee3-58a1-ab64-ac0f12b24c19
Feed Name: cybersecurityNews.com
Threat Score
High-severity local privilege escalation in Symantec Data Loss Prevention (DLP) Agent for Windows (CVE-2026-3991): a hardcoded OpenSSL configuration path allows low-privileged users to place a malicious OpenSSL.cnf and DLL, causing the edpa.exe process (running as SYSTEM) to load attacker code; Broadcom published fixes (upgrade to specified DLP versions) and administrators should patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
