Seven Windows Wonders – Critical Vulnerabilities in DNS Dynamic Updates
ID: 007e0e86-e697-577d-bc65-374e7d65c3c4
STIX ID: report--007e0e86-e697-577d-bc65-374e7d65c3c4
Feed Name: McAfee Labs Blog
Microsoft disclosed seven critical DNS Dynamic Update vulnerabilities in March 2021 (five RCEs with CVSS 9.8 and two DoS). This report analyzes CVE-2021-26877 and CVE-2021-26897 in depth, describing heap out-of-bounds read/write conditions that can lead to RCE on Primary Authoritative DNS servers, outlines exploitation prerequisites (Dynamic Update write access or a compromised domain-joined machine), states the issues are not wormable and not observed in the wild, and urges urgent patching and/or deployment of network signatures as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
