← Vulnerability feed

Vulnerability record · CVE-2006-2630 · published 27 May 2006

CVE-2006-2630: Symantec Antivirus and Client Security stack buffer overflow

Symantec · Client Security

Symantec Antivirus 10.1 and Client Security 3.1 contain a stack-based buffer overflow that remote attackers can trigger through unspecified attack vectors. The record does not identify the vulnerable component or the exact input that overflows the buffer, so defenders cannot scope exposure from the description alone. Because the flaw is remotely reachable and can lead to code execution, it is a serious pre-authentication risk for any host running the affected builds.

10.0 CVSS 2.0 High EPSS 74% · top 0.5%
10.0CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 10.0 with network reachability, no authentication and full confidentiality, integrity and availability impact, combined with a very high EPSS score, makes this an urgent patching priority despite the thin technical detail.

What it is

Symantec Antivirus 10.1 and Client Security 3.1 contain a stack-based buffer overflow that remote attackers can trigger through unspecified attack vectors. The record does not identify the vulnerable component or the exact input that overflows the buffer, so defenders cannot scope exposure from the description alone. Because the flaw is remotely reachable and can lead to code execution, it is a serious pre-authentication risk for any host running the affected builds.

Impact

A successful exploit allows remote code execution in the context of the affected Symantec service or process. That can give an attacker full control of the host, including the ability to disable protection or pivot further into the network.

Attack surface

The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not specify which protocol, port or file format carries the malicious input.

Exploitation

The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.73558 (99.4th percentile), indicating a strong likelihood of attempted exploitation. Reference tags show only patch and vendor advisory material, with no public exploit tag.

What to do

  • Apply the vendor patches referenced in the Symantec security response and Secunia advisories for Antivirus 10.1 and Client Security 3.1.
  • If patching cannot be done immediately, restrict network access to the affected Symantec services to trusted management hosts only.
  • Retire or isolate end-of-life Symantec Antivirus 10.1 and Client Security 3.1 installations that no longer receive vendor support.
  • Monitor vendor advisories for updated guidance, since the record does not name the vulnerable component or attack vector.

Detection

  • Watch for unexpected crashes or restarts of Symantec antivirus and client security processes on endpoints.
  • Alert on suspicious child processes spawned by Symantec services, which would indicate successful code execution.
  • Review network traffic to Symantec management or update ports for anomalous payloads from untrusted sources.
  • Correlate endpoint telemetry for memory corruption indicators in Symantec processes with inbound network connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-2630 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0108Symantec antivirus memory buffer overflow vulnerabilityBuffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9…EPSS 19%10.0CVE-2009-1429Symantec AMS2 Intel LANDesk CBA Remote Command ExecutionThe Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2) passes crafted packet contents directly to the CreateProcessA …EPSS 88%analysed10.0CVE-2006-6490Supportsoft scriptrunner vulnerabilityMultiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Au…EPSS 10%10.0CVE-2005-2017Symantec norton antivirus vulnerabilitySymantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with rai…EPSS 1.7%10.0CVE-2004-0487Symantec norton antivirus vulnerabilityA certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly …EPSS 6.4%10.0CVE-2004-0444Symantec client firewall vulnerabilityMultiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 throug…EPSS 13%10.0CVE-2000-0793Novell client vulnerabilityNorton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of…EPSS 2.0%9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%

Source: NIST National Vulnerability Database (record CVE-2006-2630), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.