Executive brief
Symantec Messaging Gateway contains a remote code execution vulnerability that allows an authenticated attacker to execute commands on the target machine. Following successful exploitation, an attacker may attempt to perform privilege escalation to gain higher levels of access.
Affected products
- Symantec Messaging Gateway before 10.6.3-267
Timeline
- 2017-08-10: advisory: Original vendor advisory published by Symantec
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog