Umbra Wiki cve cve/CVE-2017-6327
Back to wiki

CVE-2017-6327 — Symantec Messaging Gateway Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2017-6327 · CWE: CWE-20

CVE-2017-6327: Symantec Messaging Gateway Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Symantec
Product Symantec Messaging Gateway
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Unknown

Description

Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2017-6327

Weakness behind it

CISA records this vulnerability as an instance of CWE-20. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2017-6327
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →