PT-2004-1517 · Symantec · Norton Internet Security
Mark Litchfield
·
Published
2004-03-23
·
Updated
2017-07-11
·
CVE-2004-0363
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Norton Internet Security 2004
Description
The issue is related to a stack-based buffer overflow in the SymSpamHelper ActiveX component. This occurs when a long parameter is passed to the
LaunchCustomRuleWizard method, allowing remote attackers to execute arbitrary code.Recommendations
For Norton Internet Security 2004, consider disabling the
LaunchCustomRuleWizard method in the SymSpamHelper ActiveX component as a temporary workaround until a patch is available. Restrict access to the symspam.dll component to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Norton Internet Security