Summary
A local elevation-of-privilege vulnerability in the Symantec Data Loss Prevention (DLP) Windows Endpoint agent allows a low-privileged authenticated user to substitute or influence functionality loaded by the agent (inclusion from an untrusted control sphere). Exploitation is local and requires a valid user account; successful exploitation yields the agent's elevated privileges on the host, allowing access to sensitive data or tampering with DLP enforcement.
Why Planned Fix?
3/6Exploitation Details
Local attacker gains elevated (agent/administrative) privileges on the Windows host.
Affected Software
| Product | Affected Versions |
|---|---|
| Symantec Data Loss Prevention (DLP) Windows Endpoint | Prior to DLP 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15. |
Endpoint agent for Symantec Data Loss Prevention (DLP) that runs on Windows hosts to monitor, detect and prevent transmission of sensitive data and enforce data-loss policies.
Affected ComponentThe Symantec DLP Windows Endpoint agent component that loads or references functionality from an untrusted control sphere (allows local replacement/substitution of elements the agent loads), enabling privilege escalation when the agent runs with elevated privileges.
The Symantec DLP Windows Endpoint agent component that loads or references functionality from an untrusted control sphere (allows local replacement/substitution of elements the agent loads), enabling privilege escalation when the agent runs with elevated privileges.
Not available
Not available
Not available
Probability of exploitation in the next 30 days
Worse than 2% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Sources
| Source | Article |
|---|---|
| support.broadcom.com | https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37306 |
| www.cyber.gc.ca | https://www.cyber.gc.ca/en/alerts-advisories/symantec-security-advisory-av26-304 |
| cyberveille.esante.gouv.fr | https://cyberveille.esante.gouv.fr/alertes/broadcom-cve-2026-3991-2026-03-31 |
| cvefeed.io | https://cvefeed.io/vuln/detail/CVE-2026-3991 |
| cve.mitre.org | https://cve.mitre.org/cgi-bin/cvename.cgi?name=2026-3991 |
Priority History
Initial analysis