Microsoft disclosed and patched SIGRed (CVE-2020-1350), a critical Windows DNS Server vulnerability affecting supported and legacy Windows Server releases from 2003 through 2019. The flaw carries a CVSS score of 10.0 because an unauthenticated attacker can trigger remote code execution or denial of service, potentially enabling self-propagating attacks without user interaction.
Organizations should apply Microsoft’s security updates and restart affected DNS servers. Where patching cannot occur immediately, Microsoft’s registry-based mitigation can reduce exposure; defenders should also investigate anomalous dns.exe activity and DNS traffic exceeding 60,000 bytes, which may indicate exploitation attempts.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Elastic released public detection logic for SIGRed, including monitoring for suspicious dns.exe behavior and unusually large DNS traffic.
A public proof-of-concept exploit demonstrating denial of service for the SIGRed vulnerability was published.
Microsoft released security updates for CVE-2020-1350, affecting Windows DNS Server deployments on supported and legacy Windows Server versions.
The SIGRed Windows DNS Server remote code execution and denial-of-service flaw was assigned CVE-2020-1350.
Check Point Research sent its initial disclosure of the Windows DNS Server vulnerability later named SIGRed to Microsoft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.