CVE-2003-0994

UnknownEPSS 0.41%

Last modified

CVE-2003-0994 is a vulnerability of currently unknown severity. The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.

Description

The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges.

Metrics

EPSS Probability
0.41%

32.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
SymantecNorton Antivirus2.1
SymantecNorton Antivirus2001
SymantecNorton Antivirus2002
SymantecNorton Antivirus2003
SymantecNorton Antivirus2004
SymantecNorton Antivirusv3.0
SymantecNorton Internet Security2001
SymantecNorton Internet Security2002
SymantecNorton Internet Security2003
SymantecNorton Internet Security2004
SymantecNorton System Works2001
SymantecNorton System Works2002
SymantecNorton System Works2003
SymantecNorton System Works2004
SymantecWindows Liveupdate1.70.x
SymantecWindows Liveupdate1.90.x

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2003-0994?
The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges.
How severe is CVE-2003-0994?
Severity scoring for CVE-2003-0994 is pending analysis. The EPSS model estimates a 0.41% probability of exploitation in the next 30 days.
How do I fix CVE-2003-0994?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2003-0994?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST