CVE-2017-6327

HIGH KEV

Symantec Messaging Gateway < 10.6.3-267 - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-6327 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 1 public exploit from researchers including Philip Pettersson.

AI-analyzed exploit summary This exploit combines an authentication bypass (via encrypted `notify` parameter) and a command injection in the `db-restore` script to achieve unauthenticated remote code execution as root on Symantec Messaging Gateway.

Description

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Philip Pettersson · textwebappsjsp
https://www.exploit-db.com/exploits/42519

This exploit combines an authentication bypass (via encrypted `notify` parameter) and a command injection in the `db-restore` script to achieve unauthenticated remote code execution as root on Symantec Messaging Gateway.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Symantec Messaging Gateway (Brightmail) <= 10.6.3-2
No auth needed
Prerequisites: Network access to the web interface · Knowledge of the static encryption password for the `notify` parameter
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/Aug/28
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42519/
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100135

Scores

CVSS v3 8.8
EPSS 0.3534
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-10-20
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2017-15388
CWE
CWE-77
Status published
Products (2)
symantec/message_gateway < 10.6.3-267
Symantec Corporation/Messaging Gateway All versions prior to version 10.6.3-267
Published Aug 11, 2017
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026