Critical CVSS 10 EPSS 0.91353 2020-07 archive

Executive Summary

A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account. Windows servers that are configured as DNS servers are at risk from this vulnerability. To exploit the vulnerability, an unauthenticated attacker could send malicious requests to a Windows DNS server. The update addresses the vulnerability by modifying how Windows DNS servers handle requests.

Overview

10
CVSS CRITICAL
Critical
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
Category Remote Code Execution
Released Jul 14 2020
Last Updated Jul 14 2020
Publicly Disclosed No
CISA KEV Listed (added 2021-11-03)
Known Exploits None Known
EPSS Score 0.91353 — 0.99803 percentile
NVD CVSS 10 CRITICAL — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Changed
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 9.0

EPSS Score

0.91353
probability of exploitation in the next 30 days
0.99803 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

7 affected products
Product KB Article Severity Impact Restart Required
Windows Server 2008 for 32-bit Systems Service Pack 2 4565536 (Monthly Rollup) 4565529 (Security Only) Critical Remote Code Execution 4561670 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565536 4565529 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 4565536 (Monthly Rollup) 4565529 (Security Only) Critical Remote Code Execution 4561670 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565536 4565529 Windows Server 2008 for x64-based Systems Service Pack 2 4565536 (Monthly Rollup) 4565529 (Security Only) Critical Remote Code Execution 4561670 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565536 4565529 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 4565536 (Monthly Rollup) 4565529 (Security Only) Critical Remote Code Execution 4561670 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565536 4565529 Windows Server 2008 R2 for x64-based Systems Service Pack 1 4565524 (Monthly Rollup) 4565539 (Security Only) Critical Remote Code Execution 4561643 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565524 4565539 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 4565524 (Monthly Rollup) 4565539 (Security Only) Critical Remote Code Execution 4561643 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565524 4565539 Windows Server 2012 4565537 (Monthly Rollup) 4565535 (Security Only) Critical Remote Code Execution 4561612 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565537 4565535 Windows Server 2012 (Server Core installation) 4565537 (Monthly Rollup) 4565535 (Security Only) Critical Remote Code Execution 4561612 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565537 4565535 Windows Server 2012 R2 4565541 (Monthly Rollup) 4565540 (Security Only) Critical Remote Code Execution 4561666 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565541 4565540 Windows Server 2012 R2 (Server Core installation) 4565541 (Monthly Rollup) 4565540 (Security Only) Critical Remote Code Execution 4561666 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565541 4565540 Windows Server 2016 4565511 (Security Update) Critical Remote Code Execution Yes
Windows Server 2016 (Server Core installation) 4565511 (Security Update) Critical Remote Code Execution Yes
Windows Server 2019 4558998 (Security Update) Critical Remote Code Execution Yes
Windows Server 2019 (Server Core installation) 4558998 (Security Update) Critical Remote Code Execution Yes
Windows Server, version 1903 (Server Core installation) 4565483 (Security Update) Critical Remote Code Execution Yes
Windows Server, version 1909 (Server Core installation) 4565483 (Security Update) Critical Remote Code Execution Yes
Windows Server, version 2004 (Server Core installation) 4565503 (Security Update) Critical Remote Code Execution Yes

Patches

4 patches
Article Type Restart
4565511 Security Update Yes
4558998 Security Update Yes
4565483 Security Update Yes
4565503 Security Update Yes

Exploits & PoC

15 public PoCs
RepositoryStarsPublishedDescription
ZephrFish/CVE-2020-1350_HoneyPoC 280 2020-07-14 HoneyPoC: Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server 2000 up to Windows Server 2019.
maxpl0it/CVE-2020-1350-DoS 238 2020-07-15 A denial-of-service proof-of-concept for CVE-2020-1350
psc4re/NSE-scripts 162 2020-03-11 NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473
captainGeech42/CVE-2020-1350 18 2020-07-16 Denial of Service PoC for CVE-2020-1350 (SIGRed)
T13nn3s/CVE-2020-1350 15 2020-07-15 This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service
connormcgarr/CVE-2020-1350 11 2020-07-17 CVE-2020-1350 Proof-of-Concept
corelight/SIGRed 9 2020-07-15 Detection of attempts to exploit Microsoft Windows DNS server via CVE-2020-1350 (AKA SIGRed)
zoomerxsec/Fake_CVE-2020-1350 7 2020-07-14 Fake exploit tool, designed to rickroll users attempting to actually exploit.
mr-r3b00t/CVE-2020-1350 4 2020-07-14
graph-inc/CVE-2020-1350 2 2020-07-18 Scanner and Mitigator for CVE 2020-1350
simeononsecurity/CVE-2020-1350-Fix 2 2020-07-26 A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to restart the server. Because of the volatility of thi
jmaddington/dRMM-CVE-2020-1350-response 0 2020-07-15 Windows registry mitigation response to CVE-2020-1350
CVEmaster/CVE-2020-1350 0 2020-07-19 DNS Vulnerability - CVE-2020-1350
gdwnet/cve-2020-1350 0 2020-07-22 A powershell script to deploy the registry mitigation key for CVE-2020-1350
sty886/CVE-2020-1350-SigRed 0 2026-03-07 CVE-2020-1350的PoC

Detection Rules

Detection available

Sigma rules 4

Acknowledgments

Sagi Tzadik and Eyal Itkin from Check Point Research