A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2025-58074 represents a privilege escalation vulnerability in Norton Secure VPN installations distributed through the Microsoft Store. During the installation process, a low-privilege user can intercept and replace files before they are finalized, enabling arbitrary file deletion that bypasses security restrictions. This vulnerability affects any user installing Norton Secure VPN from the Microsoft Store on Windows systems, potentially compromising system integrity and allowing attackers to escalate from limited user accounts to higher privilege levels. The attack exploits a race condition or improper file permission handling during installation—a critical window where system files are accessible to unprivileged processes.
While CVE-2025-58074 does not currently map to specific MITRE ATT&CK techniques in public disclosures, Casky practitioners should monitor for attack patterns consistent with Privilege Escalation (TA0004) and Defense Evasion (TA0005) tactics. Extended reasoning analysis would flag suspicious installation processes where low-privilege accounts gain write access to system directories, detect unexpected file deletions during software setup, or identify permission changes that shouldn't occur during normal installation workflows. Practitioners using Casky's 754 mapped security skills would track installation anomalies, monitor file system access patterns during third-party software deployments, and correlate privilege escalation indicators with installation activity—enabling early detection of exploitation attempts before arbitrary files are deleted or system compromise occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2025-58074. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation