Vulnerability record · CVE-2007-1689 · published 16 May 2007
CVE-2007-1689: Norton 2004 ActiveX control buffer overflow via ISAlertDataCOM
Symantec · Norton Internet Security
The ISAlertDataCOM ActiveX control in ISLALERT.DLL, shipped with Norton Personal Firewall 2004 and Norton Internet Security 2004, contains a buffer overflow reachable through long arguments to its Get and Set functions. Because the control is scriptable in the browser, a remote attacker can trigger the overflow from a crafted web page and run code in the context of the logged-on user.
Description
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution with complete impact and has a very high EPSS score, but the affected 2004-era products are legacy and no KEV listing or confirmed exploit is recorded.
What it is
The ISAlertDataCOM ActiveX control in ISLALERT.DLL, shipped with Norton Personal Firewall 2004 and Norton Internet Security 2004, contains a buffer overflow reachable through long arguments to its Get and Set functions. Because the control is scriptable in the browser, a remote attacker can trigger the overflow from a crafted web page and run code in the context of the logged-on user.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the user viewing the page, allowing full compromise of the workstation. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reached over the network through the ActiveX control instantiated in a web page; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. User interaction is not explicitly stated in the record, but ActiveX exploitation normally requires the victim to load the malicious page and allow the control to run.
Exploitation
The record is not listed in CISA KEV and no reference is tagged as an exploit, so there is no confirmed in-the-wild exploitation. EPSS is high (0.64441, 99.2nd percentile), indicating a strong statistical likelihood of exploitation activity.
What to do
- Apply the Symantec vendor patch referenced in the advisory (Patch tag) or upgrade to a supported Norton product, since 2004 releases are long out of support.
- Set the kill bit for the ISAlertDataCOM CLSID in the registry to block the control from loading in Internet Explorer.
- Restrict or disable ActiveX execution in Internet Explorer and other browsers for untrusted sites.
- Remove or uninstall the legacy Norton 2004 components where they are no longer required.
Detection
- Monitor for Internet Explorer processes loading ISLALERT.DLL or instantiating the ISAlertDataCOM control.
- Alert on crash or exception events in iexplore.exe tied to ISLALERT.DLL module faults.
- Hunt for registry changes that add or remove the control's kill-bit entry under HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1689 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1689), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.