Vulnerability Description
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Message Gateway | < 10.6.3-267 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2017/Aug/28Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/100135Broken LinkThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42519/Third Party AdvisoryVDB Entry
- https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=securiVendor Advisory
- http://seclists.org/fulldisclosure/2017/Aug/28Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/100135Broken LinkThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42519/Third Party AdvisoryVDB Entry
- https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=securiVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-US Government Resource
FAQ
What is CVE-2017-6327?
CVE-2017-6327 is a vulnerability with a CVSS score of 8.8 (HIGH). The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely ...
How severe is CVE-2017-6327?
CVE-2017-6327 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6327?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Message Gateway.