CRITICAL

CVE-2020-1350

Microsoft Windows Server 2008 2020-07-14 CVSS v3.1
CVSS
10
KEV

Description

A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.

Summary dbcve.org

A remote code execution vulnerability in Windows DNS Server allows attackers to execute arbitrary code by sending specially crafted DNS requests. The vulnerability stems from improper handling of DNS protocol responses, enabling complete compromise of the affected server.

Mitigation

Apply the Microsoft security update for CVE-2020-1350 immediately to all affected Windows DNS servers. This is a critical infrastructure patch requiring urgent prioritization due to the CVSS 10 severity and wormable potential.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

96.72%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE