logo

Symantec DLP Agent Flaw Exposed Systems to Privilege Escalation Attacks

ID: 4c419542-5009-5417-a4e8-4366128263b6

STIX ID: report--4c419542-5009-5417-a4e8-4366128263b6

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Divya

...
...

A high-severity local privilege escalation (CVE-2026-3991, CVSS 7.8) in the Symantec DLP Agent allows a low-privileged user to gain SYSTEM by creating a hardcoded build-path and supplying a malicious OpenSSL configuration file and DLL; Broadcom released patches (e.g., DLP 25.1 MP1, 16.1 MP2) on March 30, 2026 and administrators should apply the updates to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.