Security Advisory

CVE-2017-16674

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-11-09 04:00:00
Last updated 2024-09-17 03:58:37
Assigner mitre
State PUBLISHED

Description

Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command and a secondary non-whitelisted command. This affects Datto Windows Agent (DWA) 1.0.5.0 and earlier. In other words, an attacker could combine this "primary/secondary" attack with the CVE-2017-16673 "rogue pairing" attack to achieve unauthenticated access to all agent machines running these older DWA versions.