Critical 17-Year Windows DNS Bug Grants Hackers Domain Admin Access

Check Point researchers uncover SIGRed, a critical 17-year-old Windows DNS vulnerability that allows unauthenticated attackers to gain Domain Administrator privileges.

Security researchers at Check Point discover SIGRed (CVE-2020-1350), a critical wormable vulnerability with a perfect 10.0 CVSS score that hides inside Windows DNS servers. This flaw lurks undetected in Microsoft code for 17 years, impacting every Windows Server version from 2003 to 2019. Attackers exploit this weakness simply by sending a malicious DNS response to a target server.

Because the Windows DNS server operates with elevated SYSTEM privileges, a successful exploit immediately grants the attacker Domain Administrator rights. This level of access effectively compromises the entire corporate infrastructure without requiring any authentication from the hacker. The vulnerability stands out because it targets the core DNS protocol rather than commonly attacked services like SMB or RDP.

Microsoft issues an emergency patch to address the severe threat, urging all system administrators to update their Windows Servers immediately. Experts warn that the wormable nature of SIGRed means it could spread rapidly across networks without human interaction, similar to historic outbreaks like EternalBlue. Organizations around the world scramble to assess their exposure and secure their domain controllers against this devastating flaw.

Read More at the original source →