PT-2017-4187 · Symantec · Symantec Messaging Gateway

Philip Pettersson

·

Publicado

2017-08-11

·

Atualizado

2025-03-21

·

CVE-2017-6327

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec Messaging Gateway versions prior to 10.6.3-267
Description The issue exists due to insufficient input validation in the goform/formEMR30 component of the Symantec Messaging Gateway. This can allow a remote attacker to elevate their privileges or execute arbitrary code. The vulnerability describes a situation where an individual may obtain the ability to execute commands remotely on a target machine or in a target process. After gaining access to the system, the attacker may attempt to elevate their privileges.
Recommendations For versions prior to 10.6.3-267, update to version 10.6.3-267 or later to resolve the issue. As a temporary workaround, consider restricting access to the goform/formEMR30 component to minimize the risk of exploitation.

Exploit

Correção

RCE

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02664
CVE-2017-6327

Produtos afetados

Symantec Messaging Gateway