BDU:2020-03377

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

10.0critical3.x
0246810

CVSS Score: 10.0/10

All CVSS Scores

CVSS 3.x
10.0

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

Уязвимость DNS-сервера операционной системы Windows связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, выполнить произвольный код при помощи специально сформированного DNS-запроса

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

bdumsrc

Related Vulnerabilities

Exploits

Exploit ID: BDU:2020-03377

Source: bdu_exploit

URL: https://bdu.fstec.ru/vul

Exploit ID: CVE-2020-1350

Source: github-poc

URL: https://github.com/sty886/CVE-2020-1350-SigRed

Recommendations

Source: bdu

Использование рекомендаций:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350

URL: https://bdu.fstec.ru/vul/2020-03377

Vulnerable Software (31)

Type: Configuration

Vendor: microsoft corp

Product: windows_server_1903

Operating System: * *

Trait:
{  "version_exact": "(server core installation)"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_1909

Operating System: * *

Trait:
{  "version_exact": "(server core installation)"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2004

Operating System: * *

Trait:
{  "version_exact": "(server core installation)"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2008

Operating System: * *

Trait:
{  "version_exact": "r2 service pack 1"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2008

Operating System: * *

Trait:
{  "version_exact": "service pack 2 (server core installation)"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2008

Operating System: * *

Trait:
{  "version_exact": "r2 service pack 1 (server core installation)"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2008

Operating System: * *

Trait:
{  "version_exact": "service pack 2"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2012

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2012

Operating System: * *

Trait:
{  "version_exact": "r2"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2012

Operating System: * *

Trait:
{  "version_exact": "r2 (server core installation)"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2012

Operating System: * *

Trait:
{  "version_exact": "(server core installation)"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2016

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2016

Operating System: * *

Trait:
{  "version_exact": "(server core installation)"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2019

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: windows_server_2019

Operating System: * *

Trait:
{  "version_exact": "(server core installation)"}

Source: bdu

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4571703

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 19041.388

Operating System: Windows 19041 build 388

Identifier: KB4565503

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 18362.959

Operating System: Windows 18362 build 959

Identifier: KB4565483

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 17763.1339

Operating System: Windows 17763 build 1339

Identifier: KB4558998

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 14393.3808

Operating System: Windows 14393 build 3808

Identifier: KB4565511

Source: msrc