Critical remote code execution vulnerability in Windows DNS server (CVE-2020-1350)

Critical remote code execution vulnerability in Windows DNS server (CVE-2020-1350)

Hello there,

 

Patch Tuesday July 2020 comes with a fix for the critical vulnerability CVE-2020-1350 in Windows DNS Server. This vulnerability is classified 'wormable' and has been given a CVSS score of 10.

 

Cause of this vulnerability:

 

This vulnerability exists due to the improper handling of requests by Windows Domain Name System (DNS) Servers.

 

Impact of this vulnerability:

 

To exploit this vulnerability, an unauthenticated attacker should send malicious requests to a Windows DNS server. If exploited, the attacker can run arbitrary codes in the context of the Local System Account. This remote code execution vulnerability has not been actively exploited yet.

 

Patches released:

 

To patch this vulnerability, initiate a sync between the Patch Manager Plus server and the Central Patch repository. Search for the relevant Patch ID or the CVE ID (CVE-2020-1350) and install it in your target systems.

  Patch ID
  Description
  29238
  2020-07 Cumulative Update for Windows 10 Version 1809 for x64-based Systems       (KB4558998) (KB4569509) (CVE-2020-1350)
  29239
  2020-07 Cumulative Update for Windows 10 Version 1809 for x86-based Systems   (KB4558998)
  29240
  2020-07 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4558998)
  29271
  2020-07 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based   Systems (KB4565524)
  29272
  2020-07 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4565524)
  29273
  2020-07 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4565524)
  29275
  2020-07 Security Only Quality Update for Windows 7 for x86-based Systems (KB4565539)
  29276
  2020-07 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems   (KB4565539)
  29277
  2020-07 Security Only Quality Update for Windows 7 for x64-based Systems (KB4565539)
  29268
  2020-07 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems   (KB4565541)
  29269
  2020-07 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4565541)
  29270
  2020-07 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4565541)
  29248
  2020-07 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4565483)
  29249
  2020-07 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4565483)
  29250
  2020-07 Cumulative Update for Windows Server
  29251
  2020-07 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4565483)
  29252
  2020-07 Cumulative Update for Windows Server
  29253
  2020-07 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB4565483)
  29234
  2020-07 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4565540)
  29235
  2020-07 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4565540)
  29236
  2020-07 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4565540)
  29278
  2020-07 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4565536)
  29279
  2020-07 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4565536)
  29280
  2020-07 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB4565529)
  29281
  2020-07 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB4565529)
  29237
  2020-07 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4565535)
  29274
  2020-07 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4565537)
  29243
  2020-07 Cumulative Update for Windows Server
  29244
  2020-07 Cumulative Update for Windows 10 Version 2004 for x86-based Systems (KB4565503)
  29245
  2020-07 Cumulative Update for Windows 10 Version 2004 for x64-based Systems (KB4565503)

Cheers,

The ManageEngine team


                New to ADSelfService Plus?