Microsoft DNS Server Integer Overflow

Strike ID:
E20-0zgm1
CVSS:
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C)
False Positive:
f
Variants:
22
Year:
2020

Description

This strike exploits an integer overflow vulnerability in Microsoft DNS Server. This vulnerability is due to improper validation of Resource Records within a Dynamic Update DNS Query. An attacker could exploit this vulnerability by sending a crafted Dynamic Update DNS query to the target server. NOTE: This form of direct attack requires the target server to have Dynamic Updates enabled for the domain used in the exploit. Successful exploitation could lead to remote code execution in context of Domain Administrator.

CVE

References