High severity8.0NVD Advisory· Published Nov 9, 2017· Updated May 13, 2026
CVE-2017-16674
CVE-2017-16674
Description
Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command and a secondary non-whitelisted command. This affects Datto Windows Agent (DWA) 1.0.5.0 and earlier. In other words, an attacker could combine this "primary/secondary" attack with the CVE-2017-16673 "rogue pairing" attack to achieve unauthenticated access to all agent machines running these older DWA versions.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.datto.com/partner-security-update-nov2017nvdMitigationPatchVendor Advisory
News mentions
0No linked articles in our index yet.