EXPOSURES › CVE-2017-6327
CVE-2017-6327
HIGH ⌖ ON CISA KEV · EXPLOITEDSymantec Messaging Gateway suffered a remote code execution vulnerability that was actively exploited in the wild.
Symantec Messaging Gateway contained an unspecified vulnerability allowing remote code execution, which attackers could leverage to execute arbitrary code and potentially escalate privileges. This failure is critical for DIB organizations because it represents an unpatched, actively exploited vulnerability that could compromise email infrastructure and lead to data exfiltration or ransomware deployment. Organizations must ensure all messaging gateway software is patched against known CVEs and monitored for active exploitation.
Shame score — The vulnerability was actively exploited in the wild (KEV list) and allowed remote code execution, indicating a severe, avoidable failure in patch management and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.
"Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions."