← Vulnerability feed

Vulnerability record · CVE-2017-6327 · published 11 August 2017

CVE-2017-6327: Symantec Messaging Gateway command injection enables remote code execution

Symantec · Message Gateway

Symantec Messaging Gateway before 10.6.3-267 is affected by a command injection flaw that allows remote code execution. An attacker who can reach the affected interface and has low-privileged access can run commands on the target, then attempt to elevate privileges. The record does not specify the exact vulnerable component or the full set of affected versions beyond the fixed build.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 36% · top 1.6% CWE-77 · Command injection
8.8CVSS 3.1 base score, v2 6.5
36%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityIt is a network-reachable remote code execution flaw with a public exploit and confirmed exploitation in CISA KEV, despite requiring low privileges.

What it is

Symantec Messaging Gateway before 10.6.3-267 is affected by a command injection flaw that allows remote code execution. An attacker who can reach the affected interface and has low-privileged access can run commands on the target, then attempt to elevate privileges. The record does not specify the exact vulnerable component or the full set of affected versions beyond the fixed build.

Impact

An attacker gains the ability to execute arbitrary commands on the Messaging Gateway host or in its process context, with high impact to confidentiality, integrity and availability. Post-exploitation privilege escalation is explicitly noted as a possible follow-on step.

Attack surface

The CVSS vector is network-reachable (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user on the network can trigger it. The description does not identify the specific endpoint or interface involved.

Exploitation

CVE-2017-6327 is listed in CISA KEV (added 2021-11-03), indicating known exploitation in the wild, and EPSS is high at roughly 0.35 (98th percentile). A public Exploit-DB entry (42519) exists, and no ransomware campaign use is documented.

What to do

  • Upgrade Symantec Messaging Gateway to 10.6.3-267 or later, per the vendor advisory.
  • If immediate upgrade is not possible, restrict network access to the Messaging Gateway management and service interfaces to trusted hosts only.
  • Audit and reduce accounts with low-privileged access to the appliance; remove or disable unused accounts.
  • Monitor for and block outbound command-and-control or unexpected process execution from the appliance host.
  • Apply the vendor's required action from the CISA KEV entry and track remediation to the 2022-05-03 due date if still outstanding.

Detection

  • Monitor Messaging Gateway logs for unexpected command execution, shell invocations, or child processes spawned by the appliance's web/service components.
  • Alert on unusual outbound network connections from the Messaging Gateway host, especially to non-standard destinations.
  • Review authentication and authorization logs for low-privileged accounts accessing administrative or command-related endpoints.
  • Hunt for known public exploit artifacts (Exploit-DB 42519) in web access logs and process telemetry.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-6327 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Symantec Messaging Gateway Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6327 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12751Symantec message gateway vulnerabilitySymantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker…EPSS 2.3%9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%8.8CVE-2017-6328Symantec message gateway cross-site request forgery vulnerabilityThe Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbrevia…EPSS 2.1%8.4CVE-2016-3646Symantec norton security improper input validation vulnerabilityThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…EPSS 18%8.4CVE-2016-3644Symantec norton security improper input validation vulnerabilityThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…EPSS 18%8.4CVE-2016-2207Symantec mail security for microsoft exchange improper input validation vulnerabilityThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…EPSS 18%7.8CVE-2016-2211Symantec AntiVirus Decomposer CAB parsing memory corruptionThe AntiVirus Decomposer engine in numerous Symantec and Norton products mishandles crafted CAB files during decompression, causing a memory buffer o…EPSS 53%analysed7.3CVE-2016-2210Symantec mail security for microsoft exchange memory buffer overflow vulnerabilityBuffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server …EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2017-6327), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.