← Vulnerability feed

Vulnerability record · CVE-2019-12751 · published 11 July 2019

CVE-2019-12751: Symantec message gateway vulnerability

Symantec · Message Gateway

Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

9.8 CVSS 3.0 Critical EPSS 2.3% · top 17.5%
9.8CVSS 3.0 base score, v2 7.5
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12751 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-6327Symantec Messaging Gateway command injection enables remote code executionSymantec Messaging Gateway before 10.6.3-267 is affected by a command injection flaw that allows remote code execution. An attacker who can reach the…KEVEPSS 36%analysed9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%8.8CVE-2017-6328Symantec message gateway cross-site request forgery vulnerabilityThe Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbrevia…EPSS 2.1%8.4CVE-2016-3646Symantec norton security improper input validation vulnerabilityThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…EPSS 18%8.4CVE-2016-3644Symantec norton security improper input validation vulnerabilityThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…EPSS 18%8.4CVE-2016-2207Symantec mail security for microsoft exchange improper input validation vulnerabilityThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…EPSS 18%7.8CVE-2016-2211Symantec AntiVirus Decomposer CAB parsing memory corruptionThe AntiVirus Decomposer engine in numerous Symantec and Norton products mishandles crafted CAB files during decompression, causing a memory buffer o…EPSS 53%analysed7.3CVE-2016-2210Symantec mail security for microsoft exchange memory buffer overflow vulnerabilityBuffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server …EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2019-12751), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.