10
CVE-2020-1350
- EPSS 91.35%
- Veröffentlicht 14.07.2020 23:15:13
- Zuletzt bearbeitet 29.10.2025 13:55:36
- Erkennungen
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version -
Microsoft ≫ Windows Server 2019 Version -
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Windows DNS Server Remote Code Execution Vulnerability
SchwachstelleMicrosoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 91.35% | 0.998 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://packetstormsecurity.com/files/158484/SIGRed-Windows-DNS-Denial-Of-Service.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1350