
CVE-2020-1350 SigRed: Wormable Windows DNS Server RCE
CVE-2020-1350 (SigRed) is a critical wormable remote code execution vulnerability in Windows DNS Server discovered by Check Point Research and patched in July 2020. A crafted DNS response can trigger a heap overflow in dns.exe, granting SYSTEM-level code execution on any Windows Server configured as a DNS resolver, with no authentication and no user interaction required. CVSS 10.0.
