Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.
https://github.com/RedyOpsResearchLabs/SEP-14.2-Arbitrary-Write