CVE-2020-0836: Windows DNS Denial of Service Vulnerability
Overview
- Severity
- High (CVSS 7.5)
- CVSS Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
- Category
- Denial of Service
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2020-Sep
- Released
- 2020-09-08
- EPSS Score
- 16.24% (percentile: 94.8%)
Description
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.
To exploit the vulnerability, an authenticated attacker could send malicious DNS queries to a target, resulting in a denial of service.
The update addresses the vulnerability by correcting how Windows DNS processes queries.
Affected Products (17)
Other
- 11769
- 11571
- 11572
- 11715
- 11647
- 10816
- 10855
- 9312
- 10287
- 9318
- 9344
- 10051
- 10049
- 10378
- 10379
- 10483
- 10543
Security Updates (12)
Acknowledgments
Quan Luo from Codesafe Team of Legendsec at Qi'anxin Group
Revision History
- 2020-09-08: Information published.