Skip to main content

Windows DNS Server Heap Overflow Vulnerability

Microsoft have released details of a buffer overflow vulnerability in the Windows DNS server. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition on an affected device.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Microsoft have released details of a buffer overflow vulnerability in the Windows DNS server. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition on an affected device.


Affected platforms

The following platforms are known to be affected:

Threat details

The vulnerability lies in how the Windows DNS server handles requests. Malicious requests sent to the server by an attacker can result in a heap buffer overflow, which can then be used to execute code in the context of the Local System Account.

For further information:


Remediation steps

Type Step

Microsoft addressed this vulnerability in their CVE-2018-8626 Security Update Guide. Users and administrators are encouraged to review this guide and apply the relevant updates.



CVE Vulnerabilities

Last edited: 14 February 2020 2:46 pm