logo

Detection rules for SIGRed vulnerability

ID: 3d535ee1-1bdc-516b-b0f2-bb11bd907809

STIX ID: report--3d535ee1-1bdc-516b-b0f2-bb11bd907809

Feed Name: Elastic Security Labs

Threat Score
90/100

Date Published: 2022-11-22

Date Updated: 2026-04-27

...
...

On July 14, 2020 Microsoft released a patch for SIGRed (CVE-2020-1350), a critical (CVSS 10) remote code execution and DoS vulnerability in Windows DNS Server affecting Windows 2003+. This report summarizes the impact and timeline, provides detection rules for endpoint and network telemetry (KQL and Packetbeat/Zeek/Suricata), and offers mitigation recommendations including applying the Microsoft security update or a registry-based workaround and maintaining backups and vulnerability scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.