Junglewise Threat Intelligence

CVE-2017-6327: Symantec Messaging Gateway Remote Code Execution Vulnerability

CVE-2017-6327 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Vendors: Symantec.

Executive brief

Symantec Messaging Gateway contains a remote code execution vulnerability that allows an authenticated attacker to execute commands on the target machine. Following successful exploitation, an attacker may attempt to perform privilege escalation to gain higher levels of access.

Affected products

  • Symantec Messaging Gateway before 10.6.3-267

Timeline

  • 2017-08-10: advisory: Original vendor advisory published by Symantec
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog