최우선 대응높음CISA KEV · 실제 악용 확인
CVE-2017-6327
Symantec Messaging Gateway Remote Code Execution Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 8.8
- EPSS
- 35.3% 백분위 98.2% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.05.03
- 공개일
- 2017.08.12
CISA KEV에 등록된 실제 악용 확인 취약점
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.
공급사 Symantec
제품 Symantec Messaging Gateway
영향 버전 All versions prior to version 10.6.3-267, < 10.6.3-267
수정 버전 10.6.3-267
Apply updates per vendor instructions.
조치 기한: 2022.05.03CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE CWE-20, CWE-77
KEV 등록일 2021.11.03
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2017-6327
EPSS 데이터 기준일 2026.06.27