CVE-2020-0761
vulnerability analysis and mitigation

Overview

CVE-2020-0761 is a remote code execution vulnerability that affects Active Directory integrated DNS (ADIDNS). The vulnerability was discovered and disclosed in March 2020, impacting Microsoft Windows Server systems that use Active Directory integrated DNS services. The vulnerability occurs when ADIDNS mishandles objects in memory, potentially allowing authenticated attackers to execute arbitrary code (MITRE CVE, Talos Blog).

Technical details

The vulnerability exists in the way Active Directory integrated DNS (ADIDNS) handles objects in memory. When exploited, it allows for authenticated code execution in the context of the Local System Account. The vulnerability has been assigned a CVSS score of 7.0, indicating a high severity level with network vector access and requiring authentication (Rapid7).

Impact

If successfully exploited, an attacker could run arbitrary code with Local System Account privileges on the affected system. This level of access would give the attacker complete control over the system, allowing them to install programs, view or modify data, and create new user accounts with full user rights (MITRE CVE).

Exploitability

The vulnerability requires authentication for exploitation. An authenticated attacker would need to send malicious requests to an Active Directory integrated DNS (ADIDNS) server to trigger the vulnerability. The attack vector is network-accessible but requires valid credentials, making it more difficult to exploit in the wild (Talos Blog).

Mitigation and workarounds

Microsoft has released security updates to address this vulnerability. The patches are available for multiple versions of Windows Server, including Server 2012, Server 2012 R2, Server 2016, and Server 2019. The update addresses the vulnerability by correcting how Active Directory integrated DNS (ADIDNS) handles objects in memory (Rapid7).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management