CISA Known Exploited Vulnerability

CVE-2020-1350

Microsoft · Windows

Microsoft Windows DNS Server Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Unknown

CISA description

Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.

Required action

Apply updates per vendor instructions.

Notes & references