Description
The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").
Affected products
- Symantec / norton_antivirus2002 – 2002
- Symantec / norton_antivirus2003 – 2003
Exploits & proofs of concept
- exploit-dbSymantec Norton AntiVirus 2002/2003 - Device Driver Memory Overwriteby Lord Yup
Updated 10m ago · 8 sources