logo

Symantec DLP Agent Vulnerability Let Attackers Escalate Privileges

ID: 53078701-4ee3-58a1-ab64-ac0f12b24c19

STIX ID: report--53078701-4ee3-58a1-ab64-ac0f12b24c19

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Abinaya

...
...

High-severity local privilege escalation in Symantec Data Loss Prevention (DLP) Agent for Windows (CVE-2026-3991): a hardcoded OpenSSL configuration path allows low-privileged users to place a malicious OpenSSL.cnf and DLL, causing the edpa.exe process (running as SYSTEM) to load attacker code; Broadcom published fixes (upgrade to specified DLP versions) and administrators should patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.