dttray.exe in Greyware Automation Products Inc Domain Time II before 5.2.b.20210331 allows remote attackers to execute arbitrary code via a URL to a malicious update in a spoofed response to the UDP query used to check for updates.
References
Link | Resource |
---|---|
https://blog.grimm-co.com/2021/04/time-for-upgrade.html | Third Party Advisory |
https://www.greyware.com/software/domaintime/ | Vendor Advisory |
https://www.greyware.com/software/domaintime/v5/installation/v5x.asp#currentVersion | Release Notes Vendor Advisory |
https://blog.grimm-co.com/2021/04/time-for-upgrade.html | Third Party Advisory |
https://www.greyware.com/software/domaintime/ | Vendor Advisory |
https://www.greyware.com/software/domaintime/v5/installation/v5x.asp#currentVersion | Release Notes Vendor Advisory |
Configurations
History
21 Nov 2024, 06:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.grimm-co.com/2021/04/time-for-upgrade.html - Third Party Advisory | |
References | () https://www.greyware.com/software/domaintime/ - Vendor Advisory | |
References | () https://www.greyware.com/software/domaintime/v5/installation/v5x.asp#currentVersion - Release Notes, Vendor Advisory |
Information
Published : 2021-07-22 13:15
Updated : 2024-11-21 06:03
NVD link : CVE-2021-30110
Mitre link : CVE-2021-30110
CVE.ORG link : CVE-2021-30110
JSON object : View
Products Affected
greyware
- domain_time_ii
CWE