CVE-2021-24078: Windows DNS Server Remote Code Execution Vulnerability
Published Feb 25, 2021
·Updated
Windows DNS Server Remote Code Execution Vulnerability
Affected Software
9 affected components
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=1909
Microsoft Windows Server 2016=2004
Microsoft Windows Server 2019
Remediation
Event History
Feb 25, 2021
CVE Published
11:01 PM
Data Sourced
11:01 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-24078?
CVE-2021-24078 is classified as a critical vulnerability allowing remote code execution on affected Windows DNS servers.
2
How do I fix CVE-2021-24078?
To fix CVE-2021-24078, apply the latest security updates provided by Microsoft for your affected Windows Server version.
3
Which versions of Windows Server are affected by CVE-2021-24078?
CVE-2021-24078 affects Windows Server 2008, 2012, 2016, and 2019 with specific service packs.
4
Can CVE-2021-24078 be exploited remotely?
Yes, CVE-2021-24078 can be exploited remotely without authentication, posing a significant risk to vulnerable systems.
5
What are the consequences of not addressing CVE-2021-24078?
Failing to address CVE-2021-24078 may allow attackers to execute arbitrary code on the vulnerable Windows DNS server, leading to data breaches and system compromise.