CVE Explorer
CVE-2026-3991
Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"affected","platforms":["Windows"],"product":"Data Loss Prevention","vendor":"Broadcom","versions":[{"status":"unaffected","version":"25.1.00100.60229"},{"status":"unaffected","version":"16.1.00200.60431"},{"status":"unaffected","version":"16.0.20009.60689"},{"status":"unaffected","version":"16.0.10112.60928"},{"status":"unaffected","version":"16.0.00215.62094"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:10d02cd983c45cf8b18db21016fd2010cb1058cd6e13e66e9c6c28e371b27aee · sha256:efdefa3df1d50ee7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:10d02cd983c45cf8b18db21016fd2010cb1058cd6e13e66e9c6c28e371b27aee · sha256:efdefa3df1d50ee7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-829","description":"CWE-829 Inclusion of functionality from untrusted control sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:10d02cd983c45cf8b18db21016fd2010cb1058cd6e13e66e9c6c28e371b27aee · sha256:efdefa3df1d50ee7… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37306"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:10d02cd983c45cf8b18db21016fd2010cb1058cd6e13e66e9c6c28e371b27aee · sha256:efdefa3df1d50ee7… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.