CVE-2020-1350
CRITICAL KEVMicrosoft Windows Server 2008 - Improper Input Validation
Title source: ruleDescription
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.
Exploits (19)
nomisec
WORKING POC
18 stars
by captainGeech42 · dos
https://github.com/captainGeech42/CVE-2020-1350
nomisec
WRITEUP
2 stars
by simeononsecurity · poc
https://github.com/simeononsecurity/CVE-2020-1350-Fix
patchapalooza
WORKING POC
by chompie1337 · client-side
https://github.com/chompie1337/SIGRed_RCE_PoC
References (3)
Scores
CVSS v3
10.0
EPSS
0.9382
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2020-10-20
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2020-12226
CWE
CWE-20
Status
published
Products (6)
microsoft/windows_server_2008
microsoft/windows_server_2008
r2 sp1
microsoft/windows_server_2012
microsoft/windows_server_2012
r2
microsoft/windows_server_2016
microsoft/windows_server_2019
Published
Jul 14, 2020
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026