← Vulnerability feed

Vulnerability record · CVE-2007-1689 · published 16 May 2007

CVE-2007-1689: Norton 2004 ActiveX control buffer overflow via ISAlertDataCOM

Symantec · Norton Internet Security

The ISAlertDataCOM ActiveX control in ISLALERT.DLL, shipped with Norton Personal Firewall 2004 and Norton Internet Security 2004, contains a buffer overflow reachable through long arguments to its Get and Set functions. Because the control is scriptable in the browser, a remote attacker can trigger the overflow from a crafted web page and run code in the context of the logged-on user.

10.0 CVSS 2.0 High EPSS 65% · top 0.8%
10.0CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw allows unauthenticated remote code execution with complete impact and has a very high EPSS score, but the affected 2004-era products are legacy and no KEV listing or confirmed exploit is recorded.

What it is

The ISAlertDataCOM ActiveX control in ISLALERT.DLL, shipped with Norton Personal Firewall 2004 and Norton Internet Security 2004, contains a buffer overflow reachable through long arguments to its Get and Set functions. Because the control is scriptable in the browser, a remote attacker can trigger the overflow from a crafted web page and run code in the context of the logged-on user.

Impact

Successful exploitation gives the attacker arbitrary code execution with the privileges of the user viewing the page, allowing full compromise of the workstation. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

Reached over the network through the ActiveX control instantiated in a web page; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. User interaction is not explicitly stated in the record, but ActiveX exploitation normally requires the victim to load the malicious page and allow the control to run.

Exploitation

The record is not listed in CISA KEV and no reference is tagged as an exploit, so there is no confirmed in-the-wild exploitation. EPSS is high (0.64441, 99.2nd percentile), indicating a strong statistical likelihood of exploitation activity.

What to do

  • Apply the Symantec vendor patch referenced in the advisory (Patch tag) or upgrade to a supported Norton product, since 2004 releases are long out of support.
  • Set the kill bit for the ISAlertDataCOM CLSID in the registry to block the control from loading in Internet Explorer.
  • Restrict or disable ActiveX execution in Internet Explorer and other browsers for untrusted sites.
  • Remove or uninstall the legacy Norton 2004 components where they are no longer required.

Detection

  • Monitor for Internet Explorer processes loading ISLALERT.DLL or instantiating the ISAlertDataCOM control.
  • Alert on crash or exception events in iexplore.exe tied to ISLALERT.DLL module faults.
  • Hunt for registry changes that add or remove the control's kill-bit entry under HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-1689 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6490Supportsoft scriptrunner vulnerabilityMultiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Au…EPSS 10%10.0CVE-2004-0444Symantec client firewall vulnerabilityMultiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 throug…EPSS 13%9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%9.3CVE-2010-0107Symantec client security memory buffer overflow vulnerabilityBuffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential…EPSS 6.5%9.3CVE-2008-0312Symantec norton 360 memory buffer overflow vulnerabilityStack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norto…EPSS 6.1%9.3CVE-2007-0447Symantec antivirus scan engine memory buffer overflow vulnerabilityHeap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple c…EPSS 6.0%9.3CVE-2007-3699Symantec antivirus scan engine vulnerabilityThe Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in th…EPSS 3.9%8.5CVE-2006-3456Symantec norton antivirus code injection vulnerabilityThe Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and Sy…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2007-1689), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.