ZeroHour

CVE-2017-6327

KEVlarge

Input Validation RCE in Symantec Messaging Gateway

CISA: Symantec Messaging Gateway Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
35%p98
Published
()
KEV added
AI analysis

CVE-2017-6327 is an input-validation flaw (CWE-20) in Symantec Messaging Gateway that allows remote code execution; the exact vulnerable code path is not described in the available data. Because the flaw is remotely triggerable, an attacker who can reach the vulnerable component can execute code on the appliance and may then pursue privilege escalation to gain higher-level access on the host. Affected organizations are those running Symantec Messaging Gateway, with risk concentrated where the appliance or its administrative interface is reachable from untrusted networks. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 with a required action to apply updates per vendor instructions, and EPSS assigns a high 35.3% probability of exploitation within 30 days (98th percentile); no public proof-of-concept is known and any ransomware association is unconfirmed.

What to do: Apply updates per vendor instructions as soon as possible, since CISA's KEV listing requires federal agencies to patch and the flaw is known exploited. In the interim, verify whether the Symantec Messaging Gateway management/administrative interface is exposed to the internet and restrict access to trusted management networks, and review appliance logs for signs of unauthorized access or code execution. Because a fixed version is not specified in the available data, confirm the current patched release with the vendor's (Symantec/Broadcom) security advisory before remediating.

Affected
Symantec Messaging Gateway
Estimated exposure
large≈10,000–100,000 deployed enterprise appliances (order-of-magnitude estimate; likely only a few thousand with management interfaces internet-exposed) — No public install-base or internet-scan counts are available in the data, so this estimate is based on the product's long history as a widely deployed on-premises enterprise email-security appliance, with only a subset of deployments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.

CISA Known Exploited Vulnerability
Affected
Symantec Symantec Messaging Gateway
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
symantec
Products
message gateway
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news