You would like to know whether Symantec Protection Engine (SPE) 9.3.x is affected by CVE-2025-7424, CVE-2025-7425, CVE-2025-6021, CVE-2025-8732, CVE-2026-23865, and CVE-2025-6052. Scanners may flag these libraries, but their implementation within SPE does not pose a security risk.
Symantec Protection Engine (SPE) 9.3.x
Symantec Protection Engine is not impacted by the following:
libxslt is used by the UpgradeUtil tool for configuration migration during SPE upgrades. It only processes trusted internal XML configuration files rather than user-supplied content.xmlBuildQName function. While other xml2 APIs might use it internally, SPE only utilizes it in the UpgradeUtil and XMLModifier tools on trusted files.UpgradeUtil and XMLModifier tools, which only run on trusted internal configuration files.FreeType is neither bundled nor referenced in SPE.GLib is not bundled or used in the SPE C++ source code.