July 15, 2020: Cybersecurity researchers today disclosed a new highly critical “wormable” vulnerability, carrying a severity score of 10 out of 10 on the CVSS scale – affecting Windows Server versions 2003 to 2019. This critical vulnerability allows an unauthenticated, remote attacker to gain domain administrator privileges over targeted servers and seize complete control of an organization’s IT infrastructure. This is accomplished by attacking a commonly open port on internal networks used to access websites called Domain Name Services (DNS), which is something like the old telephone book that listed a phone number for a person’s name. DNS converts website names to IP Addresses. This is what has the zero-day flaw that was reported today by security researchers. It is so significant that its been given a name: SigRed. Vulnerabilities that gain special names are usually bad! Think CodeRed, SQL Slammer, HeartBleed to name some recent bad ones!
A hacker exploits this vulnerability by sending a specially-crafted malicious DNS query to a Windows DNS server that leads to arbitrary code execution. Since DNS Server runs with elevated privileges [SYSTEM], a hackers can take complete and unrestricted control of the entire windows based server infrastructure. That is really, really, bad. Furthermore, security researchers reporting on this state it is “wormable” which means self-replicating, not unlike COVID-19 but worse, spreading at the speed of packets on a network to all other servers running DNS services. Read more about Worms in CyberHoot’s Cybrary articles such as SQL Slammer or the Morris Worm (1st Internet Worm ever).
Impacted Systems: Windows Server versions 2003 to 2019

Sources:
Microsoft Patching and Work-Around Knowledge Base Article
17-Year-Old Critical ‘Wormable’ RCE Vulnerability Impacts Windows DNS Servers
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
You have seen them before. A small black camera on a pole near an intersection, a solar panel on top, quietly...
Read more
Tax season keeps accountants busy, and it keeps scammers busy too. Early this summer, a CPA firm became the...
Read more
Researchers went looking for a fake photo upscaler and found something stranger: a ransomware kit an AI model...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.
