Vulnerability record · CVE-2017-6326 · published 26 June 2017
CVE-2017-6326: Symantec Messaging Gateway remote code execution
Symantec · Messaging Gateway
Symantec Messaging Gateway can be exploited to achieve remote code execution, allowing commands to be run on the target machine or within a target process. The record gives no root-cause detail (CWE is listed as insufficient information), but the network-reachable, unauthenticated nature of the flaw makes it a serious risk to exposed appliances.
Description
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication, no user interaction, and a public exploit make this an urgent patch target despite the thin description.
What it is
Symantec Messaging Gateway can be exploited to achieve remote code execution, allowing commands to be run on the target machine or within a target process. The record gives no root-cause detail (CWE is listed as insufficient information), but the network-reachable, unauthenticated nature of the flaw makes it a serious risk to exposed appliances.
Impact
An attacker can execute arbitrary commands on the affected Messaging Gateway host or in its process context, potentially leading to full compromise of the appliance and any data or credentials it handles.
Attack surface
The CVSS vector indicates network reachability with no privileges and no user interaction required. The description does not identify the specific interface or service, so the exact entry point cannot be confirmed from this record.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is very high (0.72759, 99.42nd percentile) and a public Exploit-DB entry (42251) exists, indicating mature public exploitation.
What to do
- Apply the vendor security update referenced in Symantec advisory suid=20170621_00 as the first action.
- Restrict network access to the Messaging Gateway management and mail interfaces to trusted hosts only.
- If patching cannot be done immediately, isolate the appliance on a segmented network and monitor it closely.
- Review the appliance for signs of compromise and rotate any credentials or keys stored on or passing through it.
- Track the vendor advisory for any updated guidance or workarounds.
Detection
- Monitor Messaging Gateway logs and host process activity for unexpected command execution or child processes spawned by gateway services.
- Alert on anomalous outbound connections from the appliance to unfamiliar hosts or ports.
- Review web and mail interface access logs for exploit attempts matching public PoC traffic.
- Baseline normal gateway process behavior and alert on deviations such as new binaries or shell invocations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/98893 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038785 | |
| https://www.exploit-db.com/exploits/42251/ | |
| https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year= | MitigationVendor Advisory |
| http://www.securityfocus.com/bid/98893 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038785 | |
| https://www.exploit-db.com/exploits/42251/ | |
| https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year= | MitigationVendor Advisory |
Track CVE-2017-6326 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6326), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.