CVE-2004-0445

Symantec Norton Internet Security <2004 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-0445. PoCs published by houseofdabus.

AI-analyzed exploit summary This exploit targets a denial-of-service vulnerability in Symantec firewalls by sending a malformed DNS response packet. The PoC constructs a crafted UDP packet with a malicious DNS response to trigger an infinite loop in the kernel, causing a system freeze.

Description

The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.

Exploits (1)

exploitdb WORKING POC VERIFIED
by houseofdabus · cdoswindows
https://www.exploit-db.com/exploits/299

This exploit targets a denial-of-service vulnerability in Symantec firewalls by sending a malformed DNS response packet. The PoC constructs a crafted UDP packet with a malicious DNS response to trigger an infinite loop in the kernel, causing a system freeze.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Symantec Norton Personal Firewall 2004 and related products
No auth needed
Prerequisites: Network access to the target system · Ability to send UDP packets to port 53
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1010146
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1010145
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-141.shtml
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/682110
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/6100
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16132
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021359.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1010144
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11066
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10336

Scores

EPSS 0.1105
EPSS Percentile 95.3%

Details

Status published
Products (20)
symantec/client_firewall 5.01
symantec/client_firewall 5.1.1
symantec/client_security 1.0
symantec/client_security 1.1
symantec/client_security 1.2
symantec/client_security 1.3
symantec/client_security 1.4
symantec/client_security 1.5
symantec/client_security 1.6
symantec/client_security 1.7
... and 10 more
Published Jul 07, 2004
Tracked Since Feb 18, 2026