CVE-2021-34525: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20069Patch KB5004285 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2061Patch KB5004244 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1110Patch KB5004237 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1110Patch KB5004237 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4530Patch KB5004238
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34525?
CVE-2021-34525 has a severity rating of critical, indicating a high potential for exploitation.
How do I fix CVE-2021-34525?
To fix CVE-2021-34525, apply the latest security updates released by Microsoft for the affected Windows Server versions.
What systems are affected by CVE-2021-34525?
CVE-2021-34525 affects Microsoft Windows Server 2012 R2, 2016, and 2019.
What type of vulnerability is CVE-2021-34525?
CVE-2021-34525 is classified as a remote code execution vulnerability in the Windows DNS Server.
What are potential consequences of exploiting CVE-2021-34525?
Exploitation of CVE-2021-34525 may allow attackers to run arbitrary code on affected systems, leading to data breaches or system control.