Microsoft Patches Critical Wormable DNS Server Flaw in July Update

Microsoft addresses 123 vulnerabilities in its July 2020 Patch Tuesday, highlighting a critical wormable remote code execution flaw in Windows DNS Server. Experts warn that this severe bug allows attackers to spread malware automatically without user interaction.

Microsoft releases its July 2020 Patch Tuesday updates, fixing a total of 123 vulnerabilities that include 18 critical and 105 high-severity flaws. The most alarming fix addresses CVE-2020-1350, nicknamed SIGRed, which is a wormable remote code execution vulnerability in the Windows DNS Server service. This critical flaw impacts all Windows Server versions and allows unauthenticated attackers to execute code at the Local System account level by sending specially crafted requests.

Security experts emphasize that the wormable nature of SIGRed makes it an attacker's dream, as it enables malware to spread automatically between systems without any user interaction. Because Windows DNS servers frequently double as Domain Controllers, a successful exploit grants attackers immense control and the potential to distribute ransomware similar to devastating past attacks like WannaCry and NotPetya. Microsoft notes that exploitation of this vulnerability is highly likely.

While Microsoft offers a registry edit workaround to limit the size of TCP packets processed by the server, administrators strongly prioritize applying the official patch immediately. The attack vector requires unusually large DNS packets and cannot be conducted over UDP, but the severe implications of leaving Domain Controllers exposed prompt urgent action across enterprise environments.

Read More at the original source →