CVE-2014-7287: Symantec Encryption Management Server

Medium severity, CVSS 5.0. EPSS: 1.1% chance of exploitation in the next 30 days.

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

Affected products

  • Symantec Encryption Management Server: up to and including 3.3.2
  • Symantec Pgp Universal Server: up to and including 3.3.2

Published 2015-02-01. Last modified 2026-06-17.