{"api_version":"1","generated_at":"2026-07-23T11:46:54+00:00","cve":"CVE-2003-1310","urls":{"html":"https://cve.report/CVE-2003-1310","api":"https://cve.report/api/cve/CVE-2003-1310.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1310","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1310"},"summary":{"title":"CVE-2003-1310","description":"The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka \"Device Driver Attack\").","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.osvdb.org/4362","name":"http://www.osvdb.org/4362","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://sec-labs.hack.pl/papers/win32ddc.php","name":"http://sec-labs.hack.pl/papers/win32ddc.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[sec-labs] Win32 Device Communication Vulnerabilities","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/8329","name":"http://www.securityfocus.com/bid/8329","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Symantec Norton AntiVirus Device Driver Memory Overwrite Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/9460","name":"http://secunia.com/advisories/9460","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Symantec Norton AntiVirus Device Driver Privilege Escalation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12824","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12824","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1310","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1310","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1310","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"norton_antivirus","cpe6":"2002","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1310","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"norton_antivirus","cpe6":"2003","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:19:46.141Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"4362","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/4362"},{"name":"device-driver-gain-privileges(12824)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12824"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://sec-labs.hack.pl/papers/win32ddc.php"},{"name":"8329","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/8329"},{"name":"9460","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/9460"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-08-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka \"Device Driver Attack\")."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"4362","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/4362"},{"name":"device-driver-gain-privileges(12824)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12824"},{"tags":["x_refsource_MISC"],"url":"http://sec-labs.hack.pl/papers/win32ddc.php"},{"name":"8329","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/8329"},{"name":"9460","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/9460"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1310","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka \"Device Driver Attack\")."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"4362","refsource":"OSVDB","url":"http://www.osvdb.org/4362"},{"name":"device-driver-gain-privileges(12824)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12824"},{"name":"http://sec-labs.hack.pl/papers/win32ddc.php","refsource":"MISC","url":"http://sec-labs.hack.pl/papers/win32ddc.php"},{"name":"8329","refsource":"BID","url":"http://www.securityfocus.com/bid/8329"},{"name":"9460","refsource":"SECUNIA","url":"http://secunia.com/advisories/9460"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1310","datePublished":"2006-11-30T16:00:00.000Z","dateReserved":"2006-11-30T00:00:00.000Z","dateUpdated":"2024-08-08T02:19:46.141Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:norton_antivirus:2002:*:*:*:*:*:*:*","matchCriteriaId":"8F6F3B3C-7C60-4A38-91F0-E09148DB4FD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:norton_antivirus:2003:*:*:*:*:*:*:*","matchCriteriaId":"34B1D862-2CB4-4D50-9BBA-0507FEAA1924"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1310","Ordinal":"1","Title":"CVE-2003-1310","CVE":"CVE-2003-1310","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1310","Ordinal":"1","NoteData":"The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka \"Device Driver Attack\").","Type":"Description","Title":"CVE-2003-1310"},{"CveYear":"2003","CveId":"1310","Ordinal":"2","NoteData":"2006-11-30","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1310","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}