CRITICAL
CVE-2020-1350
CVSS
10
KEV
Description
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.
Summary dbcve.org
A remote code execution vulnerability in Windows DNS Server allows attackers to execute arbitrary code by sending specially crafted DNS requests. The vulnerability stems from improper handling of DNS protocol responses, enabling complete compromise of the affected server.
Mitigation
Apply the Microsoft security update for CVE-2020-1350 immediately to all affected Windows DNS servers. This is a critical infrastructure patch requiring urgent prioritization due to the CVSS 10 severity and wormable potential.
Weakness (CWE)
CWE-20
Improper Input Validation
EPSS Score
96.72%
Probability of exploitation in next 30 days
99.9th percentile
References
http://packetstormsecurity.com/files/158484/SIGRed-Windows-DNS-Denial-Of-Service.html
Third Party Advisory, VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1350
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.