CVE-2017-6327
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.
- Affected products
- Symantec Messaging Gateway
- Symantec Message Gateway
- < 10.6.3-267
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 35.3% (98th percentile)
- Weakness
- CWE-77
- NVD status
- Analyzed
- Published
- 2017-08-11
CVE-2017-6327 at NVD
8 known exploits for CVE-2017-6327
Proof-of-concept code and exploit modules indexed by Sploitus
nmap-scripts
Symantec Messaging Gateway RestoreAction.performRestore() RCE
Symantec Messaging Gateway <= 10.6.3-2 unauthenticated root RCE(CVE-2017-6327)
Symantec Messaging Gateway 10.6.3-2 - Unauthenticated root Remote Command Execution
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
Symantec Messaging Gateway 10.6.3-2 Remote Code Execution
Immunity Canvas: BRIGHTMAIL_RESTORE