Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a21b870d29398821

Jump to content

// Workers AI · dad joke modeWhat did SIGRed say to its date? You're a signed match.

From Wikipedia, the free encyclopedia

SIGRed[1] (CVE-2020-1350) is a security vulnerability discovered in Microsoft's Domain Name System (DNS) implementation of Windows Server versions from 2003 to 2019.

To exploit the vulnerability, an unauthenticated attacker sends malicious requests to a Windows DNS server.[2] If exploited, the vulnerability could allow an attacker to run arbitrary code on a Domain Controller in the context of the Local System Account.

In Microsoft's advisory of the issue, the vulnerability was classified 'wormable' and was given a CVSS base score of 10.0.[3]

It has been the subject of a Department of Homeland Security emergency directive, instructing all government agencies to deploy patches or mitigations for it in 24 hours.[4]

The vulnerability was discovered by Check Point Software Technologies and publicly disclosed on July 14, 2020.[1]

References

[edit]
  1. 1 2 "SIGRed - Resolving Your Way into Domain Admin: Exploiting a 17 Year-old Bug in Windows DNS Servers". Check Point Research. July 14, 2020.
  2. "Emergency Directive 20-03: Mitigate Windows DNS Server Remote Code Execution Vulnerability from July 2020 Patch" (PDF). U.S. Department of Homeland Security. 2020-07-16. Archived from the original (PDF) on 2020-07-16.
  3. "July 2020 Security Update: CVE-2020-1350 Vulnerability in Windows Domain Name System (DNS) Server". Microsoft Security Response Center. Retrieved 2020-07-27.
  4. "cyber.dhs.gov - Emergency Directive 20-03". cyber.dhs.gov. 16 July 2020.