Windows DNS Server Heap Overflow Vulnerability
Microsoft have released details of a buffer overflow vulnerability in the Windows DNS server. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition on an affected device.
Summary
Microsoft have released details of a buffer overflow vulnerability in the Windows DNS server. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition on an affected device.
Affected platforms
The following platforms are known to be affected:
Threat details
The vulnerability lies in how the Windows DNS server handles requests. Malicious requests sent to the server by an attacker can result in a heap buffer overflow, which can then be used to execute code in the context of the Local System Account.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Microsoft addressed this vulnerability in their CVE-2018-8626 Security Update Guide. Users and administrators are encouraged to review this guide and apply the relevant updates. |
CVE Vulnerabilities
Last edited: 14 February 2020 2:46 pm