peter bassill · operator
$ cve CVE-2003-1310 JSON

CVE-2003-1310 EXPLOIT

4.6
MEDIUM · CVSS 2.0 · EPSS 1.2% (pctl 67)

Patch early

A public exploit exists.

Description

The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").

Scoring

CVSS4.6 (MEDIUM, v2.0)
VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS1.18% — more likely to be exploited than 67% of all CVEs
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
symantecnorton antivirus

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD