Microsoft Fixes 17-Year-Old Wormable Windows DNS Server Flaw

Microsoft releases an urgent patch for SIGRed, a critical 17-year-old vulnerability in Windows DNS Server that scores a perfect 10.0 in severity and risks handing attackers total control over corporate networks.

Microsoft releases an urgent patch for a critical, wormable vulnerability known as SIGRed that hides in Windows Domain Name System (DNS) Server. This flaw persists in all Windows Server versions from 2003 through 2019, earning a maximum severity score of 10.0 on the Common Vulnerability Scoring System (CVSS) scale. The vulnerability allows for Remote Code Execution (RCE), meaning attackers execute malicious code without any user interaction.

Check Point researchers discover the issue and report it to Microsoft in May, revealing that a simple malicious DNS response triggers the exploit. If attackers successfully leverage this flaw, they gain Domain Administrator rights and seize complete control over the target's entire IT infrastructure. This level of access enables bad actors to steal sensitive documents, intercept communications, and tamper with internal emails.

Although there are no signs of active exploitation in the wild at this time, Microsoft and the United States Cybersecurity and Infrastructure Security Agency (CISA) strongly urge organizations to install the updates immediately. Because the vulnerability is wormable, it possesses the potential to spread malware automatically between vulnerable computers. IT administrators waste no time in applying these critical security patches to protect their networks from catastrophic compromise.

Read More at the original source →