CVE-2003-1310

Symantec Norton AntiVirus 2002 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").

Exploits (1)

exploitdb WORKING POC VERIFIED
by Lord Yup · assemblylocalwindows
https://www.exploit-db.com/exploits/22980

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/4362
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/12824
Various Sources x_refsource_misc
http://sec-labs.hack.pl/papers/win32ddc.php
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8329
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/9460

Scores

EPSS 0.0053
EPSS Percentile 67.2%

Details

Status published
Products (2)
symantec/norton_antivirus 2002
symantec/norton_antivirus 2003
Published Dec 31, 2003
Tracked Since Feb 18, 2026