A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.
Se presenta una vulnerabilidad de ejecución de código remota en los servidores de Windows Domain Name System cuando presentan un fallo al manejar apropiadamente las peticiones, también se conoce como "Windows DNS Server Remote Code Execution Vulnerability"
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:L/Au:N/C:C/I:C/A:C
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary |
en
CWE-20
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| microsoft | windows_server_2008 | - | <built-in method update of dict object at 0x7e60e884f400> | Operating System |
| microsoft | windows_server_2008 | r2 | <built-in method update of dict object at 0x7e60e884e340> | Operating System |
| microsoft | windows_server_2012 | - | <built-in method update of dict object at 0x7e60e884c700> | Operating System |
| microsoft | windows_server_2012 | r2 | <built-in method update of dict object at 0x7e6112379e80> | Operating System |
| microsoft | windows_server_2016 | - | <built-in method update of dict object at 0x7e60e884da00> | Operating System |
| microsoft | windows_server_2019 | - | <built-in method update of dict object at 0x7e60e884eb40> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |