← Vulnerability feed

Vulnerability record · CVE-2004-0363 · published 15 April 2004

CVE-2004-0363: Norton AntiSpam ActiveX Control Stack Buffer Overflow

Symantec · Norton Antispam

The SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as shipped with Norton Internet Security 2004, contains a stack-based buffer overflow. A long parameter passed to the LaunchCustomRuleWizard method overwrites stack memory, allowing remote code execution. The flaw matters because the component is reachable from a web page, so simply browsing a malicious site can trigger it.

7.5 CVSS 2.0 High EPSS 67% · top 0.7%
7.5CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with no authentication and a very high EPSS score, though the product is legacy and exploitation requires user interaction.

What it is

The SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as shipped with Norton Internet Security 2004, contains a stack-based buffer overflow. A long parameter passed to the LaunchCustomRuleWizard method overwrites stack memory, allowing remote code execution. The flaw matters because the component is reachable from a web page, so simply browsing a malicious site can trigger it.

Impact

An attacker can execute arbitrary code in the context of the user running the browser, giving full control of the affected workstation. No privilege escalation is required beyond the logged-in user's rights.

Attack surface

Reached over the network through the ActiveX control instantiated by a web page; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is needed. Exploitation requires the victim to visit a malicious page and allow the control to load, so user interaction is effectively required.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.66567 (99.25th percentile), indicating a high modeled likelihood of exploitation. References include vendor and patch advisories, but no public exploit code is confirmed in the record.

What to do

  • Apply the Symantec patch referenced in the vendor advisory (nextgenss.com advisory and sarc.com bulletin) or upgrade to a supported Norton product.
  • Disable or kill-bit the SymSpamHelper/symspam.dll ActiveX control in Internet Explorer and other browsers that load ActiveX.
  • Restrict browsing to trusted sites and enforce ActiveX allow-listing via Group Policy where the control is not required.
  • Remove Norton AntiSpam 2004 / Norton Internet Security 2004 from endpoints that no longer need it.

Detection

  • Monitor for browser processes loading symspam.dll, especially from unexpected paths or after visiting untrusted sites.
  • Alert on crashes or exceptions in symspam.dll or the hosting browser process.
  • Hunt for outbound connections or child processes spawned by the browser shortly after ActiveX instantiation.
  • Review proxy and DNS logs for known malicious or exploit-hosting domains tied to ActiveX drive-by campaigns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0363 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2004-0363), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.