dttray.exe in Greyware Automation Products Inc Domain Time II before 5.2.b.20210331 allows remote attackers to execute arbitrary code via a URL to a malicious update in a spoofed response to the UDP query used to check for updates.
References
Link | Resource |
---|---|
https://blog.grimm-co.com/2021/04/time-for-upgrade.html | Third Party Advisory |
https://www.greyware.com/software/domaintime/ | Vendor Advisory |
https://www.greyware.com/software/domaintime/v5/installation/v5x.asp#currentVersion | Release Notes Vendor Advisory |
Configurations
History
No history.
Information
Published : 2021-07-22 13:15
Updated : 2021-08-06 16:56
NVD link : CVE-2021-30110
Mitre link : CVE-2021-30110
CVE.ORG link : CVE-2021-30110
JSON object : View
Products Affected
greyware
- domain_time_ii
CWE