First published: Thu Feb 25 2021(Updated: )
Windows DNS Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =20h2 | |
Microsoft Windows Server 2016 | =1909 | |
Microsoft Windows Server 2016 | =2004 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24078 is classified as a critical vulnerability allowing remote code execution on affected Windows DNS servers.
To fix CVE-2021-24078, apply the latest security updates provided by Microsoft for your affected Windows Server version.
CVE-2021-24078 affects Windows Server 2008, 2012, 2016, and 2019 with specific service packs.
Yes, CVE-2021-24078 can be exploited remotely without authentication, posing a significant risk to vulnerable systems.
Failing to address CVE-2021-24078 may allow attackers to execute arbitrary code on the vulnerable Windows DNS server, leading to data breaches and system compromise.