cve-2020-1350

CRITICAL CVSS 10.0 cisa_known_exploited
Description

Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.

Timeline
Published
2021-11-03
Last Modified
2021-11-03
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 10.0,
  "datePublished": "2021-11-03",
  "dateUpdated": "2021-11-03",
  "description": "Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.",
  "dueDate": "2022-05-03",
  "id": "CVE-2020-1350",
  "kev_catalogs": [
    "cisa"
  ],
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "Reference CISA's ED 20-03 (https://www.cisa.gov/news-events/directives/ed-20-03-mitigate-windows-dns-server-remote-code-execution-vulnerability-july-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-03. https://nvd.nist.gov/vuln/detail/CVE-2020-1350",
  "product": "Windows",
  "requiredAction": "Apply updates per vendor instructions.",
  "severity": "CRITICAL",
  "source": "cisa_known_exploited",
  "title": "Microsoft Windows DNS Server Remote Code Execution Vulnerability",
  "vendor": "Microsoft"
}
Enrichment data
View JSON API Download JSON