Vulnerability record · CVE-2017-6327 · published 11 August 2017
CVE-2017-6327: Symantec Messaging Gateway command injection enables remote code execution
Symantec · Message Gateway
Symantec Messaging Gateway before 10.6.3-267 is affected by a command injection flaw that allows remote code execution. An attacker who can reach the affected interface and has low-privileged access can run commands on the target, then attempt to elevate privileges. The record does not specify the exact vulnerable component or the full set of affected versions beyond the fixed build.
Description
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a network-reachable remote code execution flaw with a public exploit and confirmed exploitation in CISA KEV, despite requiring low privileges.
What it is
Symantec Messaging Gateway before 10.6.3-267 is affected by a command injection flaw that allows remote code execution. An attacker who can reach the affected interface and has low-privileged access can run commands on the target, then attempt to elevate privileges. The record does not specify the exact vulnerable component or the full set of affected versions beyond the fixed build.
Impact
An attacker gains the ability to execute arbitrary commands on the Messaging Gateway host or in its process context, with high impact to confidentiality, integrity and availability. Post-exploitation privilege escalation is explicitly noted as a possible follow-on step.
Attack surface
The CVSS vector is network-reachable (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user on the network can trigger it. The description does not identify the specific endpoint or interface involved.
Exploitation
CVE-2017-6327 is listed in CISA KEV (added 2021-11-03), indicating known exploitation in the wild, and EPSS is high at roughly 0.35 (98th percentile). A public Exploit-DB entry (42519) exists, and no ransomware campaign use is documented.
What to do
- Upgrade Symantec Messaging Gateway to 10.6.3-267 or later, per the vendor advisory.
- If immediate upgrade is not possible, restrict network access to the Messaging Gateway management and service interfaces to trusted hosts only.
- Audit and reduce accounts with low-privileged access to the appliance; remove or disable unused accounts.
- Monitor for and block outbound command-and-control or unexpected process execution from the appliance host.
- Apply the vendor's required action from the CISA KEV entry and track remediation to the 2022-05-03 due date if still outstanding.
Detection
- Monitor Messaging Gateway logs for unexpected command execution, shell invocations, or child processes spawned by the appliance's web/service components.
- Alert on unusual outbound network connections from the Messaging Gateway host, especially to non-standard destinations.
- Review authentication and authorization logs for low-privileged accounts accessing administrative or command-related endpoints.
- Hunt for known public exploit artifacts (Exploit-DB 42519) in web access logs and process telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6327 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Symantec Messaging Gateway Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2017/Aug/28 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/100135 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/42519/ | Third Party AdvisoryVDB Entry |
| https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year= | Vendor Advisory |
| http://seclists.org/fulldisclosure/2017/Aug/28 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/100135 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/42519/ | Third Party AdvisoryVDB Entry |
| https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year= | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6327 | US Government Resource |
Track CVE-2017-6327 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6327), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.