Symantec Protection Engine vulnerability assessment for CVE-2025-7424 and 2026 series CVEs
search cancel

Symantec Protection Engine vulnerability assessment for CVE-2025-7424 and 2026 series CVEs

book

Article ID: 446570

calendar_today

Updated On:

Products

Protection Engine for NAS

Issue/Introduction

You would like to know whether Symantec Protection Engine (SPE) 9.3.x is affected by CVE-2025-7424, CVE-2025-7425, CVE-2025-6021, CVE-2025-8732, CVE-2026-23865, and CVE-2025-6052. Scanners may flag these libraries, but their implementation within SPE does not pose a security risk.

Environment

Symantec Protection Engine (SPE) 9.3.x

Resolution

Symantec Protection Engine is not impacted by the following:

  • CVE-2025-7424, CVE-2025-7425: No impact. libxslt is used by the UpgradeUtil tool for configuration migration during SPE upgrades. It only processes trusted internal XML configuration files rather than user-supplied content.
  • CVE-2025-6021: No impact. The code does not directly reference the xmlBuildQName function. While other xml2 APIs might use it internally, SPE only utilizes it in the UpgradeUtil and XMLModifier tools on trusted files.
  • CVE-2025-8732: No impact. This vulnerability applies to the UpgradeUtil and XMLModifier tools, which only run on trusted internal configuration files.
  • CVE-2026-23865: No impact. FreeType is neither bundled nor referenced in SPE.
  • CVE-2025-6052: No impact. GLib is not bundled or used in the SPE C++ source code.