CVE-2017-16674: Datto Windows Agent
High severity, CVSS 8.0. EPSS: 0.7% chance of exploitation in the next 30 days.
Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command and a secondary non-whitelisted command. This affects Datto Windows Agent (DWA) 1.0.5.0 and earlier. In other words, an attacker could combine this "primary/secondary" attack with the CVE-2017-16673 "rogue pairing" attack to achieve unauthenticated access to all agent machines running these older DWA versions.
Affected products
- Datto Windows Agent: up to and including 1.0.5.0
Published 2017-11-09. Last modified 2026-06-17.