<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SIGRed (CVE-2020-1350) is a wormable, critical vulnerability! in Threats</title>
    <link>https://community.isc2.org/t5/Threats/SIGRed-CVE-2020-1350-is-a-wormable-critical-vulnerability/m-p/37304#M26</link>
    <description>&lt;P&gt;SIGRed (CVE-2020-1350) is a wormable, critical vulnerability (CVSS base score of 10.0) in the Windows DNS server that affects Windows Server versions 2003 to 2019, and can be triggered by a malicious DNS response. As the service is running in elevated privileges (SYSTEM), if exploited successfully, an attacker is granted Domain Administrator rights, effectively compromising the entire corporate infrastructure. Here's the &lt;A href="https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/" target="_blank" rel="noopener"&gt;research article&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:34:29 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2023-10-09T09:34:29Z</dc:date>
    <item>
      <title>SIGRed (CVE-2020-1350) is a wormable, critical vulnerability!</title>
      <link>https://community.isc2.org/t5/Threats/SIGRed-CVE-2020-1350-is-a-wormable-critical-vulnerability/m-p/37304#M26</link>
      <description>&lt;P&gt;SIGRed (CVE-2020-1350) is a wormable, critical vulnerability (CVSS base score of 10.0) in the Windows DNS server that affects Windows Server versions 2003 to 2019, and can be triggered by a malicious DNS response. As the service is running in elevated privileges (SYSTEM), if exploited successfully, an attacker is granted Domain Administrator rights, effectively compromising the entire corporate infrastructure. Here's the &lt;A href="https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/" target="_blank" rel="noopener"&gt;research article&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:34:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/SIGRed-CVE-2020-1350-is-a-wormable-critical-vulnerability/m-p/37304#M26</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:34:29Z</dc:date>
    </item>
  </channel>
</rss>

