CVE-2003-0994
Summary
| CVE | CVE-2003-0994 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-02-03 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Norton Antivirus | 2.1 | All | ms_exchange | All |
| Application | Symantec | Norton Antivirus | 2001 | All | All | All |
| Application | Symantec | Norton Antivirus | 2001 | All | pro | All |
| Application | Symantec | Norton Antivirus | 2002 | All | All | All |
| Application | Symantec | Norton Antivirus | 2002 | All | pro | All |
| Application | Symantec | Norton Antivirus | 2003 | All | All | All |
| Application | Symantec | Norton Antivirus | 2003 | All | pro | All |
| Application | Symantec | Norton Antivirus | 2004 | All | pro | All |
| Application | Symantec | Norton Antivirus | v3.0 | All | handhelds | All |
| Application | Symantec | Norton Internet Security | 2001 | All | All | All |
| Application | Symantec | Norton Internet Security | 2001 | All | pro | All |
| Application | Symantec | Norton Internet Security | 2002 | All | All | All |
| Application | Symantec | Norton Internet Security | 2002 | All | pro | All |
| Application | Symantec | Norton Internet Security | 2003 | All | All | All |
| Application | Symantec | Norton Internet Security | 2003 | All | pro | All |
| Application | Symantec | Norton Internet Security | 2004 | All | All | All |
| Application | Symantec | Norton Internet Security | 2004 | All | pro | All |
| Application | Symantec | Norton System Works | 2001 | All | All | All |
| Application | Symantec | Norton System Works | 2002 | All | All | All |
| Application | Symantec | Norton System Works | 2003 | All | All | All |
| Application | Symantec | Norton System Works | 2004 | All | All | All |
| Application | Symantec | Windows Liveupdate | 1.70.x | All | All | All |
| Application | Symantec | Windows Liveupdate | 1.90.x | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/3428 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| [Full-Disclosure] SRT2004-01-9-1022 - Symantec LiveUpdate allows local users to become SYSTEM | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| Secure Network Operations, Inc. - Research | af854a3a-2127-422b-91ae-364da2661108 | www.secnetops.biz | |
| 'Re: SRT2004-01-9-1022 - Symantec LiveUpdate allows local users to become' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.