SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    SIGRed (CVE-2020-1350) Critical Remote Code Execution Vulnerability on Microsoft DNS Servers
Date    Thursday July 16 2020, @05:01AM
Author    martyb
Topic   
from the Security dept.
https://soylentnews.org/article.pl?sid=20/07/15/1945219

dluttrell writes:

PATCH NOW - SIGRed - CVE-2020-1350 - Microsoft DNS Server Vulnerability:

Yesterday, Microsoft released a patch for CVE-2020-1350, fixing a critical vulnerability in it's[sic] DNS server. The vulnerability is 17 years old. All current versions of Microsoft's server back to 2003 are affected. The vulnerability earned a CVSS score of 10, indicating that it allows a full remote system compromise without any authentication. An exploit could likely spread without user interaction ("wormable").

A server is vulnerable if the DNS role is enabled. Note that Active Directory and Kerberos require DNS, and domain controllers usually have the DNS role enabled. This will put the domain controller at risk!

The vulnerability is triggered by an oversized DNS response containing a "SIG" record.

The basic exploit flow would look like:

To trigger the exploit, the size of the response has to exceed 64kBytes. However, this does not mean that the attacker has to send more then 64kBytes (the attacker can't! DNS replies over TCP max out at 64kBytes). Instead, the attacker's response will take advantage of "pointers", to compress the response. It will be expanded (and trigger the exploit) on the victim's DNS server.

For more technical information, see: https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/


Original Submission

Links

  1. "PATCH NOW - SIGRed - CVE-2020-1350 - Microsoft DNS Server Vulnerability" - https://isc.sans.edu/diary/26356
  2. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=42111

© Copyright 2023 - SoylentNews, All Rights Reserved

printed from SoylentNews, SIGRed (CVE-2020-1350) Critical Remote Code Execution Vulnerability on Microsoft DNS Servers on 2023-07-19 23:40:23