Vulnerability Details CVE-2017-6324
The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially malicious macro through despite the administrator having the 'disarm' functionality enabled. This constitutes a 'bypass' of the disarm functionality resident to the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.0%
CVSS Severity
CVSS v3 Score 7.3
CVSS v2 Score 7.5
Products affected by CVE-2017-6324
-
cpe:2.3:a:symantec:messaging_gateway:10.0
-
cpe:2.3:a:symantec:messaging_gateway:10.0.1
-
cpe:2.3:a:symantec:messaging_gateway:10.0.2
-
cpe:2.3:a:symantec:messaging_gateway:10.0.3
-
cpe:2.3:a:symantec:messaging_gateway:10.5.0
-
cpe:2.3:a:symantec:messaging_gateway:10.5.1
-
cpe:2.3:a:symantec:messaging_gateway:10.5.2
-
cpe:2.3:a:symantec:messaging_gateway:10.5.4
-
cpe:2.3:a:symantec:messaging_gateway:10.6.0
-
cpe:2.3:a:symantec:messaging_gateway:10.6.1
-
cpe:2.3:a:symantec:messaging_gateway:10.6.2
-
cpe:2.3:a:symantec:messaging_gateway:9.5
-
cpe:2.3:a:symantec:messaging_gateway:9.5.1
-
cpe:2.3:a:symantec:messaging_gateway:9.5.2
-
cpe:2.3:a:symantec:messaging_gateway:9.5.3
-
cpe:2.3:a:symantec:messaging_gateway:9.5.4