Patch Tuesday (July 2020): Microsoft Fixes a 17-Year-Old Flaw Found in Windows DNS Se
#1
Exclamation 
Quote:
[Image: heimdal-logo.svg]

The vulnerability has been rated 10.0 in terms of severity

The recurring monthly security updates from Microsoft are now out. In the July 2020 Patch Tuesday, the Redmond giant released updates to fix 123 vulnerabilities found in Windows and other software. The most notable one is a critical, wormable vulnerability spotted in Windows Server versions from 2003 to 2019. According to Microsoft, the flaw could be exploited anytime soon, so it’s crucial for all organizations to patch their systems as soon as possible as an entire organization’s network could become compromised.

Even though none of the vulnerabilities have been spotted being exploited in the wild so far, we urge you to prioritize this serious security issue and apply your updates immediately!

CVE-2020-1350 has been given a CVSS severity score of 10.0

CVE-2020-1350, dubbed SigRed, is the most recent major concern for system administrators in charge of patching. This is a Critical Remote Code Execution (RCE) vulnerability in Windows DNS Server that has been classified as a wormable (self-propagating) vulnerability.

It has been rated by Microsoft with a CVSS base score of 10.0, being the result of a flaw in Microsoft’s DNS server role implementation. It affects all Windows Server versions (keep in mind that non-Microsoft DNS Servers are not affected). Basically, an exploitable vulnerability in Windows Server could allow attackers to install malware by sending a specially crafted DNS request.

Why is this vulnerability highly dangerous?

All wormable vulnerabilities can be passed on from endpoint to endpoint through malware without the need for any user interaction. The Windows DNS server is the main network component and if a compromised user with elevated privilege becomes compromised, the attacker could also be granted admin rights. In some cases, the vulnerability can be leveraged remotely through the browser. The attacker could take control of the server and perform malicious actions such as gain complete access to the network, steal the employees’ credentials, etc.

No one has reported the weakness having been exploited in the wild (as of yet), but Microsoft still advises everyone to apply the updates.
 
Quote:“While this vulnerability is not currently known to be used in active attacks, it is essential that customers apply Windows updates to address this vulnerability as soon as possible”.

“DNS is a foundational networking component and commonly installed on Domain Controllers, so a compromise could lead to significant service interruptions and the compromise of high-level domain accounts.”, writes Microsoft.

As reported by ZDNet, the issue has been lingering in Microsoft’s code for 17 years, yet there is no evidence that it has ever been abused in the real world.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AdGuard Browser Extension 5.1.101 (MV3 s...
AdGuard Browser Ex...harlan4096 — 07:39
Europe just launched DNS4EU, a public DN...
DNS is one of the ...harlan4096 — 07:36
LibreOffice 25.2.4
LibreOffice 25.2.4...harlan4096 — 07:25
K-Lite Codec Pack 19.0.0 / 18.9.7 Update
Changes in 19.0.0:...harlan4096 — 07:24
Microsoft Edge 137.0.3296.68
Version 137.0.3296...harlan4096 — 07:23

[-]
Birthdays
Today's Birthdays
avatar (48)rapedDow
avatar (43)Johnsonsyday
avatar (48)Groktus
avatar (40)efodo
Upcoming Birthdays
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (38)biobdam
avatar (41)zacforat
avatar (46)NemrokReks
avatar (37)Barrackleve
avatar (39)Julioagopy
avatar (49)aolaupitt2558
avatar (47)vadimTob
avatar (37)leannauu4
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
There are no staff members currently online.

>