Microsoft Windows DNS Server Remote Code Execution Vulnerability
Microsoft · Windows
Date added (CISA)
2021-11-03
Remediation due
2022-05-03
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.