Critical Windows DNS Server Flaw SIGRed Demands Immediate Patching

A highly critical, wormable vulnerability known as SIGRed affects Windows DNS Servers and allows unauthenticated attackers to gain Domain Admin rights. Organizations are urged to apply Microsoft's July Patch Tuesday updates immediately to prevent automated network compromises.

Microsoft addresses a severe, 10.0 CVSS-scored vulnerability known as SIGRed (CVE-2020-1350) that affects Windows DNS Servers. This flaw stems from an integer overflow in how the server handles obsolete SIG records, enabling remote, unauthenticated attackers to execute arbitrary code and gain Domain Admin privileges. Because DNS servers frequently double as domain controllers, a successful exploit compromises the entire network infrastructure.

The attack requires tricking a vulnerable DNS server into querying a malicious server that replies with an unusually long SIG record over TCP. Microsoft explicitly warns that this vulnerability is wormable, meaning malware could potentially spread across networks without any human interaction. While no active malware exploiting this flaw is known at publication, its wormable nature makes it an urgent threat reminiscent of recent issues like SMBGhost.

Data from Forescout's Device Cloud reveals that nearly 3% of observed Windows Servers, totaling over 7,000 devices, expose the vulnerable TCP port 53. Affected operating systems include Windows Server versions 2008, 2012, 2016, 2019, and Windows 10 versions 1903, 1909, and 2004. IT administrators must apply the July Patch Tuesday updates immediately to mitigate this significant risk to enterprise networks.

Read More at the original source →