Exploitation Summary
EIP tracks 2 public exploits for CVE-2004-0363.
PoCs published by Metasploit, MC, including Metasploit module exploits/windows/browser/nis2004_antispam.
AI-analyzed exploit summary This exploit targets a stack buffer overflow in Norton AntiSpam 2004 via the LaunchCustomRuleWizard() method in symspam.dll. It uses a heap spray technique to achieve remote code execution on vulnerable systems.
Description
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.
Exploits (2)
This exploit targets a stack buffer overflow in Norton AntiSpam 2004 via the LaunchCustomRuleWizard() method in symspam.dll. It uses a heap spray technique to achieve remote code execution on vulnerable systems.
This Metasploit module exploits a stack buffer overflow in Norton AntiSpam 2004 via the LaunchCustomRuleWizard() method of the SymSpamHelper ActiveX control. It uses heap spraying and a long string to trigger arbitrary code execution.