Vulnerability record · CVE-2006-2630 · published 27 May 2006
CVE-2006-2630: Symantec Antivirus and Client Security stack buffer overflow
Symantec · Client Security
Symantec Antivirus 10.1 and Client Security 3.1 contain a stack-based buffer overflow that remote attackers can trigger through unspecified attack vectors. The record does not identify the vulnerable component or the exact input that overflows the buffer, so defenders cannot scope exposure from the description alone. Because the flaw is remotely reachable and can lead to code execution, it is a serious pre-authentication risk for any host running the affected builds.
Description
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication and full confidentiality, integrity and availability impact, combined with a very high EPSS score, makes this an urgent patching priority despite the thin technical detail.
What it is
Symantec Antivirus 10.1 and Client Security 3.1 contain a stack-based buffer overflow that remote attackers can trigger through unspecified attack vectors. The record does not identify the vulnerable component or the exact input that overflows the buffer, so defenders cannot scope exposure from the description alone. Because the flaw is remotely reachable and can lead to code execution, it is a serious pre-authentication risk for any host running the affected builds.
Impact
A successful exploit allows remote code execution in the context of the affected Symantec service or process. That can give an attacker full control of the host, including the ability to disable protection or pivot further into the network.
Attack surface
The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not specify which protocol, port or file format carries the malicious input.
Exploitation
The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.73558 (99.4th percentile), indicating a strong likelihood of attempted exploitation. Reference tags show only patch and vendor advisory material, with no public exploit tag.
What to do
- Apply the vendor patches referenced in the Symantec security response and Secunia advisories for Antivirus 10.1 and Client Security 3.1.
- If patching cannot be done immediately, restrict network access to the affected Symantec services to trusted management hosts only.
- Retire or isolate end-of-life Symantec Antivirus 10.1 and Client Security 3.1 installations that no longer receive vendor support.
- Monitor vendor advisories for updated guidance, since the record does not name the vulnerable component or attack vector.
Detection
- Watch for unexpected crashes or restarts of Symantec antivirus and client security processes on endpoints.
- Alert on suspicious child processes spawned by Symantec services, which would indicate successful code execution.
- Review network traffic to Symantec management or update ports for anomalous payloads from untrusted sources.
- Correlate endpoint telemetry for memory corruption indicators in Symantec processes with inbound network connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-2630 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-2630), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.