VulnerabilityModified
CVE-2003-1310
The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").
MEDIUM 4.6EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- symantec/norton antivirus
- Source
- cve@mitre.org
References
- http://sec-labs.hack.pl/papers/win32ddc.php
- http://secunia.com/advisories/9460Vendor Advisory
- http://www.osvdb.org/4362
- http://www.securityfocus.com/bid/8329Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12824
- http://sec-labs.hack.pl/papers/win32ddc.php
- http://secunia.com/advisories/9460Vendor Advisory
- http://www.osvdb.org/4362
- http://www.securityfocus.com/bid/8329Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12824
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.