ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Experts Urge Immediate Patching of Wormable DNS Server Bug

criticalExploit / PoC exploited in the wildimportance 60CVE-2020-1350CVE-2020-1346

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-1346
An elevation of privilege vulnerability exists when the Windows Modules Installer improperly handles file operations, aka 'Windows Modules Installer Elevation o

An elevation of privilege vulnerability exists when the Windows Modules Installer improperly handles file operations, aka 'Windows Modules Installer Elevation of Privilege Vulnerability'.

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2020-1350
Wormable Unauthenticated RCE in Microsoft Windows DNS Server

CVE-2020-1350 is a critical (CVSS 10.0) remote code execution vulnerability in the DNS Server role of Microsoft Windows Server, caused by improper input handling (CWE-20) when the server fails to properly process crafted DNS requests, notably malicious DNS signature (SIG) records delivered over TCP. An unauthenticated attacker can trigger it by sending a crafted DNS query that forces the vulnerable DNS server to perform an upstream lookup and receive a malicious response, overflowing a heap buffer. Successful exploitation yields code execution with SYSTEM privileges on the DNS server, which is very often an Active Directory domain controller, giving the attacker control of the host and typically the entire domain; the flaw is considered wormable because compromised DNS servers can propagate attacks to other servers they query. Any Windows Server 2008, 2012, 2016, or 2019 host running the DNS Server role is affected — internet-facing DNS servers are directly explovable, while internal DNS servers can be reached via malicious DNS responses passed through firewalls. The flaw was fixed in Microsoft's July 2020 updates, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, required action: apply vendor updates), carries EPSS of 91.4% (100th percentile), and appears in the NSA's top-25 list of flaws exploited by Chinese state-sponsored hackers; no public PoC is cataloged in this dataset and ransomware use is listed as unknown.

Do: Apply the July 2020 (or later) Microsoft security updates for each affected Windows Server release, prioritizing internet-facing DNS servers and domain controllers; if patching must be delayed, apply Microsoft's registry-based workaround limiting TCP DNS packet size (TcpReceivePacketSize = 0xFF00) and restart the DNS Server service. Inventory hosts with the DNS Server role installed and review their TCP/53 exposure, especially any resolvers reachable from the internet, and confirm remediation per CISA's required action.

10.091% KEV
  • microsoft windows server 2008 All builds with the DNS Server role enabled, prior to the July 2020 security updates
  • microsoft windows server 2012 All builds with the DNS Server role enabled, prior to the July 2020 security updates
  • microsoft windows server 2016 All builds with the DNS Server role enabled, prior to the July 2020 security updates
  • +1 more
masshundreds of thousands of internet-exposed Windows DNS servers (est.), with millions of total deployments including internal domain controllers
Full article336 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has released yet another gargantuan security update this month, fixing 123 vulnerabilities including 18 marked critical.

The July Patch Tuesday is close to the largest ever update, which came last month, fixing 129 bugs, and is the fifth month in a row that the Redmond giant has issued patches for over 100 software flaws.

Although none of the bugs listed are known to be actively exploited in the wild, four of the critical vulnerabilities are market as “exploitation more likely.” 

Gill Langston, head security nerd at SolarWinds MSP, urged administrators to tackle one of these, CVE-2020-1350, first.

“While there are vulnerabilities listed in many areas this month, I cannot stress enough how important the patch for Microsoft DNS server is for this month. While restarting your DNS server or the Active Directory server it is a part of was likely not in this week’s plans, you should really consider making this patch your number one priority,” he argued.

“Since nearly everyone is running DNS with Active Directory, bad actors are likely to see the high target count this offers and develop exploits rather quickly. If you cannot patch it, at least set aside some time to deploy the workaround to protect this important part of your infrastructure until you can deploy the patch.”

The 18 critical CVEs affect Windows, IE, Office, SharePoint, .Net Framework and Visual Studio. Ivanti senior product manager, Todd Schell, said the OS, browser and Office should be prioritized, but that SharePoint, .Net and Visual Studio should not be neglected.

“Microsoft has also included Servicing Stack Updates (SSUs) for all Windows versions in this month’s updates that resolves a critical vulnerability, which is a first,” he added.

CVE-2020-1346 is an elevation of privilege vulnerability in Windows Modules Installer that could allow an attacker to gain elevated privileges on the affected system. In this case the attacker would need to execute code on the target system. This vulnerability affects all Windows OSs including Windows 7, Server 2008 and 2008 R2.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/experts-immediate-patching/