Vulnerability record · CVE-2004-0363 · published 15 April 2004
CVE-2004-0363: Norton AntiSpam ActiveX Control Stack Buffer Overflow
Symantec · Norton Antispam
The SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as shipped with Norton Internet Security 2004, contains a stack-based buffer overflow. A long parameter passed to the LaunchCustomRuleWizard method overwrites stack memory, allowing remote code execution. The flaw matters because the component is reachable from a web page, so simply browsing a malicious site can trigger it.
Description
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution with no authentication and a very high EPSS score, though the product is legacy and exploitation requires user interaction.
What it is
The SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as shipped with Norton Internet Security 2004, contains a stack-based buffer overflow. A long parameter passed to the LaunchCustomRuleWizard method overwrites stack memory, allowing remote code execution. The flaw matters because the component is reachable from a web page, so simply browsing a malicious site can trigger it.
Impact
An attacker can execute arbitrary code in the context of the user running the browser, giving full control of the affected workstation. No privilege escalation is required beyond the logged-in user's rights.
Attack surface
Reached over the network through the ActiveX control instantiated by a web page; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is needed. Exploitation requires the victim to visit a malicious page and allow the control to load, so user interaction is effectively required.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.66567 (99.25th percentile), indicating a high modeled likelihood of exploitation. References include vendor and patch advisories, but no public exploit code is confirmed in the record.
What to do
- Apply the Symantec patch referenced in the vendor advisory (nextgenss.com advisory and sarc.com bulletin) or upgrade to a supported Norton product.
- Disable or kill-bit the SymSpamHelper/symspam.dll ActiveX control in Internet Explorer and other browsers that load ActiveX.
- Restrict browsing to trusted sites and enforce ActiveX allow-listing via Group Policy where the control is not required.
- Remove Norton AntiSpam 2004 / Norton Internet Security 2004 from endpoints that no longer need it.
Detection
- Monitor for browser processes loading symspam.dll, especially from unexpected paths or after visiting untrusted sites.
- Alert on crashes or exceptions in symspam.dll or the hosting browser process.
- Hunt for outbound connections or child processes spawned by the browser shortly after ActiveX instantiation.
- Review proxy and DNS logs for known malicious or exploit-hosting domains tied to ActiveX drive-by campaigns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0363 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0363), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.