CVE-2020-1350

CRITICAL KEV

Microsoft Windows Server 2008 - Improper Input Validation

Title source: rule

Description

A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.

Exploits (19)

nomisec TROJAN 280 stars
by ZephrFish · poc
https://github.com/ZephrFish/CVE-2020-1350_HoneyPoC
nomisec WORKING POC 237 stars
by maxpl0it · dos
https://github.com/maxpl0it/CVE-2020-1350-DoS
nomisec SCANNER 163 stars
by psc4re · poc
https://github.com/psc4re/NSE-scripts
nomisec WORKING POC 18 stars
by captainGeech42 · dos
https://github.com/captainGeech42/CVE-2020-1350
nomisec SCANNER 15 stars
by T13nn3s · poc
https://github.com/T13nn3s/CVE-2020-1350
nomisec WORKING POC 11 stars
by connormcgarr · dos
https://github.com/connormcgarr/CVE-2020-1350
nomisec WRITEUP 9 stars
by corelight · poc
https://github.com/corelight/SIGRed
nomisec TROJAN 7 stars
by zoomerxsec · poc
https://github.com/zoomerxsec/Fake_CVE-2020-1350
nomisec WORKING POC 4 stars
by mr-r3b00t · poc
https://github.com/mr-r3b00t/CVE-2020-1350
nomisec WRITEUP 2 stars
by simeononsecurity · poc
https://github.com/simeononsecurity/CVE-2020-1350-Fix
nomisec SCANNER 2 stars
by graph-inc · poc
https://github.com/graph-inc/CVE-2020-1350
nomisec WORKING POC
by sty886 · poc
https://github.com/sty886/CVE-2020-1350-SigRed
nomisec WORKING POC
by gdwnet · poc
https://github.com/gdwnet/cve-2020-1350
nomisec STUB
by CVEmaster · poc
https://github.com/CVEmaster/CVE-2020-1350
nomisec WRITEUP
by jmaddington · poc
https://github.com/jmaddington/dRMM-CVE-2020-1350-response
patchapalooza WORKING POC
by keyboxdzd · poc
https://gitee.com/keyboxdzd/SIGRed_RCE_PoC
patchapalooza WORKING POC
by chompie1337 · client-side
https://github.com/chompie1337/SIGRed_RCE_PoC
patchapalooza WORKING POC
by cracklee · poc
https://gitee.com/cracklee/cve-2020-1350
patchapalooza WORKING POC
by lmdy · poc
https://gitee.com/lmdy/CVE-2020-1350-DoS

Scores

CVSS v3 10.0
EPSS 0.9382
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-10-20
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2020-12226
CWE
CWE-20
Status published
Products (6)
microsoft/windows_server_2008
microsoft/windows_server_2008 r2 sp1
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
microsoft/windows_server_2016
microsoft/windows_server_2019
Published Jul 14, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026