A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.
https://www.tenable.com/blog/one-year-later-what-can-we-learn-from-zerologon
https://www.tenable.com/blog/microsoft-s-march-2021-patch-tuesday-addresses-82-cves-cve-2021-26411
https://www.tenable.com/blog/microsoft-s-september-2020-patch-tuesday-addresses-129-cves
https://github.com/trishab0807-lgtm/home-network-scanner
https://github.com/sty886/CVE-2020-1350-SigRed
https://github.com/Gorstak-Zadar/Patcher
https://github.com/nichxlxs/cve-research
https://github.com/joxeankoret/diaphora
https://github.com/gdwnet/cve-2020-1350
https://github.com/graph-inc/CVE-2020-1350
https://github.com/jmaddington/dRMM-CVE-2020-1350-response
https://github.com/corelight/SIGRed
https://github.com/T13nn3s/CVE-2020-1350
https://github.com/psc4re/NSE-scripts
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1350
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
Published: 2020-07-14
Updated: 2026-06-17
Named Vulnerability: SigRedNamed Vulnerability: SIGRedKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 10
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
EPSS: 0.91353