← לוח פגיעויות

CVE-2020-1350

קריטית 10.0 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft Windows DNS Server Remote Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.

מדדים

CVSS 3.1
10.0 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
92% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-20

מוצרים מושפעים

microsoft: windows server 2008; microsoft: windows server 2012; microsoft: windows server 2016; microsoft: windows server 2019

קישורים