CVE-2020-1350 — Windows DNS Server Remote Code Execution Vulnerability
Executive Summary
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account. Windows servers that are configured as DNS servers are at risk from this vulnerability. To exploit the vulnerability, an unauthenticated attacker could send malicious requests to a Windows DNS server. The update addresses the vulnerability by modifying how Windows DNS servers handle requests.
Overview
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows Server 2008 for 32-bit Systems Service Pack 2 4565536 (Monthly Rollup) 4565529 (Security Only) Critical Remote Code Execution 4561670 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565536 4565529 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 4565536 (Monthly Rollup) 4565529 (Security Only) Critical Remote Code Execution 4561670 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565536 4565529 Windows Server 2008 for x64-based Systems Service Pack 2 4565536 (Monthly Rollup) 4565529 (Security Only) Critical Remote Code Execution 4561670 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565536 4565529 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 4565536 (Monthly Rollup) 4565529 (Security Only) Critical Remote Code Execution 4561670 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565536 4565529 Windows Server 2008 R2 for x64-based Systems Service Pack 1 4565524 (Monthly Rollup) 4565539 (Security Only) Critical Remote Code Execution 4561643 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565524 4565539 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 4565524 (Monthly Rollup) 4565539 (Security Only) Critical Remote Code Execution 4561643 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565524 4565539 Windows Server 2012 4565537 (Monthly Rollup) 4565535 (Security Only) Critical Remote Code Execution 4561612 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565537 4565535 Windows Server 2012 (Server Core installation) 4565537 (Monthly Rollup) 4565535 (Security Only) Critical Remote Code Execution 4561612 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565537 4565535 Windows Server 2012 R2 4565541 (Monthly Rollup) 4565540 (Security Only) Critical Remote Code Execution 4561666 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565541 4565540 Windows Server 2012 R2 (Server Core installation) 4565541 (Monthly Rollup) 4565540 (Security Only) Critical Remote Code Execution 4561666 Base: 10.0 Temporal: 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Yes 4565541 4565540 Windows Server 2016 | 4565511 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 4565511 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 | 4558998 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 4558998 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server, version 1903 (Server Core installation) | 4565483 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server, version 1909 (Server Core installation) | 4565483 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server, version 2004 (Server Core installation) | 4565503 (Security Update) |
Critical | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
4565511 |
Security Update | Yes |
4558998 |
Security Update | Yes |
4565483 |
Security Update | Yes |
4565503 |
Security Update | Yes |
Exploits & PoC
15 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| ZephrFish/CVE-2020-1350_HoneyPoC | 280 | 2020-07-14 | HoneyPoC: Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server 2000 up to Windows Server 2019. |
| maxpl0it/CVE-2020-1350-DoS | 238 | 2020-07-15 | A denial-of-service proof-of-concept for CVE-2020-1350 |
| psc4re/NSE-scripts | 162 | 2020-03-11 | NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473 |
| captainGeech42/CVE-2020-1350 | 18 | 2020-07-16 | Denial of Service PoC for CVE-2020-1350 (SIGRed) |
| T13nn3s/CVE-2020-1350 | 15 | 2020-07-15 | This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service |
| connormcgarr/CVE-2020-1350 | 11 | 2020-07-17 | CVE-2020-1350 Proof-of-Concept |
| corelight/SIGRed | 9 | 2020-07-15 | Detection of attempts to exploit Microsoft Windows DNS server via CVE-2020-1350 (AKA SIGRed) |
| zoomerxsec/Fake_CVE-2020-1350 | 7 | 2020-07-14 | Fake exploit tool, designed to rickroll users attempting to actually exploit. |
| mr-r3b00t/CVE-2020-1350 | 4 | 2020-07-14 | |
| graph-inc/CVE-2020-1350 | 2 | 2020-07-18 | Scanner and Mitigator for CVE 2020-1350 |
| simeononsecurity/CVE-2020-1350-Fix | 2 | 2020-07-26 | A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to restart the server. Because of the volatility of thi |
| jmaddington/dRMM-CVE-2020-1350-response | 0 | 2020-07-15 | Windows registry mitigation response to CVE-2020-1350 |
| CVEmaster/CVE-2020-1350 | 0 | 2020-07-19 | DNS Vulnerability - CVE-2020-1350 |
| gdwnet/cve-2020-1350 | 0 | 2020-07-22 | A powershell script to deploy the registry mitigation key for CVE-2020-1350 |
| sty886/CVE-2020-1350-SigRed | 0 | 2026-03-07 | CVE-2020-1350的PoC |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 4
Acknowledgments
Sagi Tzadik and Eyal Itkin from Check Point Research