CVE-2021-34442: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
Other sources
Windows DNS Server Denial of Service Vulnerability This CVE ID is unique from CVE-2021-33745, CVE-2021-34444, CVE-2021-34499.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20069Patch KB5004285 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23409Patch KB5004302 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25661Patch KB5004307 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21167Patch KB5004299 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4530Patch KB5004238 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1110Patch KB5004237 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2061Patch KB5004244 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1110Patch KB5004237
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34442?
CVE-2021-34442 is rated as critical, indicating the potential for remote code execution.
How do I fix CVE-2021-34442?
To fix CVE-2021-34442, apply the latest security updates provided by Microsoft for affected versions of Windows Server.
What versions of Windows Server are affected by CVE-2021-34442?
CVE-2021-34442 affects multiple versions including Windows Server 2008, 2012, 2016, and 2019.
What type of attack does CVE-2021-34442 enable?
CVE-2021-34442 allows attackers to execute arbitrary code remotely, potentially leading to a complete system compromise.
Can CVE-2021-34442 cause a denial of service?
Yes, CVE-2021-34442 can lead to denial of service conditions in addition to remote code execution vulnerabilities.