CVE-2003-0470 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 8.7% (pctl 95)
Patch early
A public exploit exists.
Description
Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service, allows remote attackers to execute arbitrary code via a long argument to CompareVersionStrings.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 8.7% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-08-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| symantec | security check |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Symantec Security Check RuFSI - ActiveX Control Buffer Overflow | 2003-06-23 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006014.html
- http://marc.info/?l=bugtraq&m=105647537823877&w=2
- http://secunia.com/advisories/9091
- http://securitytracker.com/id?1007029
- http://www.kb.cert.org/vuls/id/527228
- http://www.securityfocus.com/bid/8008
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12423
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006014.html
- http://marc.info/?l=bugtraq&m=105647537823877&w=2
- http://secunia.com/advisories/9091
- http://securitytracker.com/id?1007029
- http://www.kb.cert.org/vuls/id/527228
- http://www.securityfocus.com/bid/8008
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12423
→ the Explorer · watch your stack · NVD