Record summary

CVE-2017-6327 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit. CISA lists CVE-2017-6327 in KEV.

Description

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Oct 20, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListAll versions prior to version 10.6.3-267affected

Proofs of concept

1

Catalogued exploits

ExploitDBSymantec Messaging Gateway 10.6.3-2 - Root Remote Command ExecutionExploitDB exploitby Philip PetterssonNot analyzed1 file
ExploitDB

PoC details

References

6