Back to overview

CVE-2020-1350

CRITICAL KEV CISA Exploitation: ACTIVE
10.0
CVSS 3.1
Description
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.

Metadata

CVE ID
CVE-2020-1350
State
PUBLISHED
Assigner
microsoft
Reserved
2019-11-04 00:00 UTC
Published
2020-07-14 22:54 UTC
Last updated
2025-10-21 23:35 UTC
Primary CWE
CWE-20
CWE-20 Improper Input Validation
Vendor / Product
Microsoft / Windows Server
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Microsoft Windows DNS Server Remote Code Execution Vulnerability
Vendor
Microsoft
Product
Windows
Added to KEV
2021-11-03
Due date
2022-05-03
Ransomware
Not known
Required action
Apply updates per vendor instructions.
CISA description
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
Affected products (4)
VendorProductPlatformVersions
Microsoft Windows Server 2019, 2019 (Core installation), 2016, 2016 (Core installation) …
Microsoft Windows Server, version 1903 (Server Core installation) unspecified
Microsoft Windows Server, version 1909 (Server Core installation) unspecified
Microsoft Windows Server, version 2004 (Server Core installation) unspecified
Weakness (CWE)
CWESourceDescription
cna Remote Code Execution
CWE-20 adp CWE-20 Improper Input Validation
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview