LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-6327: Symantec Messaging Gateway Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-6327 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform…

CVE-2017-6327 is a remote code execution vulnerability in Symantec Messaging Gateway. It stems from improper input validation and can let an attacker run code on the appliance. Because messaging gateways often sit at the edge of email infrastructure and handle untrusted traffic, successful abuse can give an attacker a foothold from which to attempt further privilege escalation. Public detail on exact mechanics is limited; confirm all version and configuration specifics against the vendor advisory.

IT and security teams should treat this as a high-priority review item for any Symantec Messaging Gateway deployments still in use. CISA notes the vulnerability allows remote code execution and that an attacker may also pursue privilege-escalating actions afterward. Known ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In products of this class, the software fails to adequately check or sanitize data it receives before acting on it. An attacker who can reach the vulnerable interface can supply crafted input that the gateway processes incorrectly, leading to execution of attacker-controlled code in the context of the affected service.

Exact exploit steps, required authentication state, and precise attack vectors are not specified in the available summary. Treat the issue as an unspecified remote code execution flaw in Symantec Messaging Gateway. Once code execution is achieved, the attacker is positioned to attempt privilege escalation or lateral movement inside the environment, consistent with the CISA description. Do not assume particular ports, protocols, or payload formats; verify those details only from the vendor advisory.

Am I affected? How to find it in your systems

Symantec Messaging Gateway is typically deployed as an email security appliance or virtual appliance that inspects inbound and outbound mail, often in the DMZ or at the mail perimeter. Inventory any hosts, virtual machines, or appliances running this product.

How to remediate

Patch first. Apply the updates provided by the vendor for Symantec Messaging Gateway exactly as described in the official advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls.

If your data may have been exposed

Actively exploited remote code execution vulnerabilities on perimeter mail systems can lead to unauthorized access, data theft, or further compromise of connected infrastructure. If you have reason to believe an appliance was exposed or abused before patching, follow your incident-response process: isolate affected systems where appropriate, preserve logs, rotate credentials that may have been handled by the gateway, and assess whether mail content or credentials could have been accessed. You can run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in prior breaches and to prioritize further credential hygiene.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSymantec · Symantec Messaging Gateway
WeaknessCWE-20
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities