CVE-2017-6324: High severity symantec messaging gateway for service providers vulnerability
The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially malicious macro through despite the administrator having the 'disarm' functionality enabled. This constitutes a 'bypass' of the disarm functionality resident to the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6324?
CVE-2017-6324 is considered a medium severity vulnerability due to its potential to bypass security measures.
How do I fix CVE-2017-6324?
To fix CVE-2017-6324, update to a version of Symantec Messaging Gateway that is higher than 10.6.2 to ensure proper handling of malicious attachments.
What type of vulnerability is CVE-2017-6324?
CVE-2017-6324 is a bypass vulnerability that affects the disarm functionality of the Symantec Messaging Gateway.
What does the disarm functionality do in relation to CVE-2017-6324?
The disarm functionality in the Symantec Messaging Gateway is intended to neutralize potentially harmful macros in email attachments, which CVE-2017-6324 circumvents.
Which versions of Symantec Messaging Gateway are affected by CVE-2017-6324?
CVE-2017-6324 affects all versions of Symantec Messaging Gateway up to and including version 10.6.2.