dttray.exe in Greyware Automation Products Inc Domain Time II before 5.2.b.20210331 allows remote attackers to execute arbitrary code via a URL to a malicious update in a spoofed response to the UDP query used to check for updates.
Link | Tags |
---|---|
https://www.greyware.com/software/domaintime/ | vendor advisory |
https://blog.grimm-co.com/2021/04/time-for-upgrade.html | third party advisory |
https://www.greyware.com/software/domaintime/v5/installation/v5x.asp#currentVersion | release notes vendor advisory |