QID 375819
Date Published: 2021-09-02
QID 375819: Domain Time Arbitrary Code Execution Vulnerability
Domain Time is simply the most professional, comprehensive, and technically-advanced network time solution.
CVE-2021-30110: dttray.exe in Greyware Automation Products Inc Domain Time II before 5.2.b.20210331 allows remote attackers to execute arbitrary code via a URL to a malicious update in a spoofed response to the UDP query used to check for updates.
Affected Product:
Domain Time II before 5.2.b.20210331
Detection Logic(Authenticated):
This QID will first check the 'dttray.exe' existence and then check the version.
Successful exploitation could allows remote attackers to execute arbitrary code via a URL to a malicious update in a spoofed response to the UDP query used to check for updates.
Solution
For more information please visit advisory
Vendor References
CVEs related to QID 375819
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-30110 |
|