HIGH · 7.2

CVE-2003-0994

The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and N...

Vulnerability Description

The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SymantecNorton Antivirus2.1
SymantecNorton Internet Security2001
SymantecNorton System Works2001
SymantecWindows Liveupdate1.70.x

References

FAQ

What is CVE-2003-0994?

CVE-2003-0994 is a vulnerability with a CVSS score of 7.2 (HIGH). The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and N...

How severe is CVE-2003-0994?

CVE-2003-0994 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-0994?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Norton Antivirus, Symantec Norton Internet Security, Symantec Norton System Works, Symantec Windows Liveupdate.