Microsoft Patches Critical Wormable DNS Server Flaw in July Update
Microsoft's July 2020 Patch Tuesday fixes 123 vulnerabilities, headlined by a critical, wormable remote code execution flaw in Windows DNS Server known as SIGRed. The update also addresses several serious Hyper-V RemoteFX vulnerabilities.
Microsoft releases its July 2020 Patch Tuesday update, addressing a total of 123 CVEs across a wide range of its software products. This marks the fifth consecutive month where Microsoft patches over 100 vulnerabilities, covering systems like Windows, Microsoft Office, Internet Explorer, Edge, Visual Studio, and Azure DevOps.
The most alarming issue in this release is CVE-2020-1350, a remote code execution vulnerability in Windows DNS Server dubbed "SIGRed." This flaw earns a maximum 10.0 CVSSv3 score due to its wormable nature, meaning it spreads between vulnerable computers without user interaction. The bug exists in how the DNS server parses requests and has silently impacted Windows Server versions from 2003 to 2019 for the past 17 years.
Because a compromised DNS server causes severe organizational damage, Microsoft strongly recommends installing the patch immediately. The company even provides a rare patch for the end-of-life Windows Server 2008 and offers a TCP registry workaround for organizations that need more time to update their systems. Additionally, this release resolves six remote code execution vulnerabilities in Hyper-V RemoteFX vGPU.