PT-2017-4187 · Symantec · Symantec Messaging Gateway
Philip Pettersson
·
Publicado
2017-08-11
·
Atualizado
2025-03-21
·
CVE-2017-6327
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec Messaging Gateway versions prior to 10.6.3-267
Description
The issue exists due to insufficient input validation in the goform/formEMR30 component of the Symantec Messaging Gateway. This can allow a remote attacker to elevate their privileges or execute arbitrary code. The vulnerability describes a situation where an individual may obtain the ability to execute commands remotely on a target machine or in a target process. After gaining access to the system, the attacker may attempt to elevate their privileges.
Recommendations
For versions prior to 10.6.3-267, update to version 10.6.3-267 or later to resolve the issue. As a temporary workaround, consider restricting access to the goform/formEMR30 component to minimize the risk of exploitation.
Exploit
Correção
RCE
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Symantec Messaging Gateway