Vulnerability record · CVE-2020-1350 · published 14 July 2020
CVE-2020-1350: Windows DNS Server improper input validation remote code execution
Microsoft · Windows Server 2008
Windows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication or user interaction, and has a critical CVSS score of 10, making it a top-tier risk for any exposed DNS server.
Description
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10 with network reachability, no authentication, and KEV listing plus very high EPSS make this an urgent patch-first issue.
What it is
Windows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication or user interaction, and has a critical CVSS score of 10, making it a top-tier risk for any exposed DNS server.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the DNS service, potentially gaining full control of the server. Because the scope is changed, compromise can extend beyond the DNS service to the host and its domain role.
Attack surface
Reached over the network via DNS requests to a vulnerable Windows DNS server; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N). Any server running the affected DNS role and reachable on port 53 is exposed.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS 30-day probability is about 0.91 (99.8th percentile), indicating active exploitation is expected. No ransomware campaign use is documented in this record.
What to do
- Apply the Microsoft security update referenced in the vendor advisory immediately.
- Restrict DNS service exposure to trusted networks and block port 53 from untrusted sources where feasible.
- Enable and review DNS server logging and monitor for anomalous query patterns.
- Verify all Windows DNS servers in the environment, including legacy 2008/2012/2016/2019 builds, are patched.
- Track KEV remediation due date (2022-05-03) and confirm closure.
Detection
- Monitor DNS server logs for malformed or unusually large DNS requests that trigger service errors or crashes.
- Alert on unexpected process creation or code execution originating from the DNS service process.
- Watch for DNS service restarts or crashes correlated with inbound query spikes.
- Use network monitoring to flag anomalous DNS traffic from external sources to internal DNS servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-1350 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Windows DNS Server Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158484/SIGRed-Windows-DNS-Denial-Of-Service.html | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/158484/SIGRed-Windows-DNS-Denial-Of-Service.html | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1350 | US Government Resource |
Track CVE-2020-1350 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-1350), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.