CVE-2003-0470

Symantec Security Check - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0470. PoCs published by Cesar Cerrudo.

AI-analyzed exploit summary This exploit targets a boundary condition error in the RuFSI Utility Class ActiveX control. By invoking the CompareVersionStrings method with long strings, it can trigger a buffer overflow, potentially leading to arbitrary code execution with the privileges of the user running the web browser.

Description

Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service, allows remote attackers to execute arbitrary code via a long argument to CompareVersionStrings.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Cesar Cerrudo · textdoswindows
https://www.exploit-db.com/exploits/22816

This exploit targets a boundary condition error in the RuFSI Utility Class ActiveX control. By invoking the CompareVersionStrings method with long strings, it can trigger a buffer overflow, potentially leading to arbitrary code execution with the privileges of the user running the web browser.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: RuFSI Utility Class ActiveX control (clsid:69DEAF94-AF66-11D3-BEC0-00105AA9B6AE)
No auth needed
Prerequisites: Victim must visit a malicious webpage · ActiveX control must be installed and enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006014.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1007029
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8008
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105647537823877&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/9091
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/12423
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/527228

Scores

EPSS 0.0870
EPSS Percentile 94.4%

Details

Status published
Products (1)
symantec/security_check
Published Aug 07, 2003
Tracked Since Feb 18, 2026