PT-2004-1518 · Symantec · Norton Internet Security

Mark Litchfield

·

Published

2004-03-23

·

Updated

2017-07-11

·

CVE-2004-0364

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Norton Internet Security version 2004
Description The issue concerns the WrapNISUM ActiveX component, specifically the WrapUM.dll file, which is marked as safe for scripting. This marking allows remote attackers to execute arbitrary programs by utilizing the LaunchURL method.
Recommendations For Norton Internet Security version 2004, consider disabling the WrapUM.dll file or restricting its use to prevent exploitation until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0364

Affected Products

Norton Internet Security