CVE-2020-1228
published 2020-09-11CVE-2020-1228: A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability…
PriorityP334medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
4.50%
90.4th percentile
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.
To exploit the vulnerability, an authenticated attacker could send malicious DNS queries to a target, resulting in a denial of service.
The update addresses the vulnerability by correcting how Windows DNS processes queries.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < publication | publication |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_version_1903 | — | — |
| msrc | windows_server_version_1909 | — | — |
| msrc | windows_server_version_2004 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pf2q-6q6p-25p9: A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2020-0836 [HIGH] CWE-20 GHSA-pf2q-6q6p-25p9: A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1228.
GHSA
GHSA-h78g-2jmr-346w: A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2020-1228 [HIGH] GHSA-h78g-2jmr-346w: A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-0836.
Chrome
Stable Channel Update for Desktop: CVE-2023-1228
vendor_chrome·2023-03-07·CVSS 4.3
CVE-2023-1228 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-1228
Stable Channel Update for Desktop
CVE-2023-1228: Insufficient policy enforcement in Intents. Reported by Axel Chong on 2022-09-18 [$2000][ 1160485 ] Medium CVE-2023-1229: Inappropriate implementation in Permission prompts
Reported by Thomas Orlita on 2020-12-20 [$2000][ 1404230 ] Medium CVE-2023-1230: Inappropriate implementation in WebApp Installs
Severity: medium
Microsoft
Windows DNS Denial of Service Vulnerability
vendor_msrc·2020-09-08·CVSS 7.5
CVE-2020-1228 [HIGH] Windows DNS Denial of Service Vulnerability
Windows DNS Denial of Service Vulnerability
Description: A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.
To exploit the vulnerability, an authenticated attacker could send malicious DNS queries to a target, resulting in a denial of service.
The update addresses the vulnerability by correcting how Windows DNS processes queries.
Microsoft Windows DNS: Microsoft Windows DNS
Microsoft: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/
No detection rules found.
No public exploits indexed.
Trendmicro
September Patch Tuesday Updates Exchange, SharePoint
blogs_trendmicro·2020-09-09·CVSS 7.5
[HIGH] September Patch Tuesday Updates Exchange, SharePoint
## September Patch Tuesday Updates Exchange, SharePoint
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities.
By: Trend Micro 2020/09/09 Read time: ( words)
Save to Folio
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities. Of the total number, 23 have been rated Critical and 105 as Important. No zero days have been observed, but four vulnerabilities are under close scrutiny for their potential abuse. Specifically, CVE-2020-16875 can be exploited for remote code execution (RCE), CVE-2020-1596 for man-in-the-middle (MiTM) attacks, while CVE-2020-0836 and CVE-2020-1228 can be abused for domain name system (DNS) denial of service (D
Trendmicro
September Patch Tuesday Updates Exchange, SharePoint
blogs_trendmicro·2020-09-09·CVSS 7.5
[HIGH] September Patch Tuesday Updates Exchange, SharePoint
## September Patch Tuesday Updates Exchange, SharePoint
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities.
By: Trend Micro Sep 09, 2020 Read time: ( words)
Save to Folio
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities. Of the total number, 23 have been rated Critical and 105 as Important. No zero days have been observed, but four vulnerabilities are under close scrutiny for their potential abuse. Specifically, CVE-2020-16875 can be exploited for remote code execution (RCE), CVE-2020-1596 for man-in-the-middle (MiTM) attacks, while CVE-2020-0836 and CVE-2020-1228 can be abused for domain name system (DNS) denial of service
Trendmicro
September Patch Tuesday Updates Exchange, SharePoint
blogs_trendmicro·2020-09-09·CVSS 7.5
[HIGH] September Patch Tuesday Updates Exchange, SharePoint
# September Patch Tuesday Updates Exchange, SharePoint
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities.
By: Trend Micro
2020/09/09
Read time: ( words)
Save to Folio
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities. Of the total number, 23 have been rated Critical and 105 as Important. No zero days have been observed, but four vulnerabilities are under close scrutiny for their potential abuse. Specifically, CVE-2020-16875 can be exploited for remote code execution (RCE), CVE-2020-1596 for man-in-the-middle (MiTM) attacks, while CVE-2020-0836 and CVE-2020-1228 can be abused for domain name system (DNS) denial of service (D
Tenable
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
blogs_tenable·2020-09-08
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2020-6851 openjpeg: Heap-based buffer overflow in opj_t1_clbl_decode_processor()
bugzilla·2020-01-13·CVSS 7.5
CVE-2020-6851 [HIGH] CVE-2020-6851 openjpeg: Heap-based buffer overflow in opj_t1_clbl_decode_processor()
CVE-2020-6851 openjpeg: Heap-based buffer overflow in opj_t1_clbl_decode_processor()
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in libopenjp2.so.
Upstream Issue:
https://github.com/uclouvain/openjpeg/issues/1228
Discussion:
Created mingw-openjpeg tracking bugs for this issue:
Affects: fedora-31 [bug 1790514]
Created openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1790512]
Created openjpeg2 tracking bugs for this issue:
Affects: epel-all [bug 1790515]
Affects: fedora-all [bug 1790513]
---
Upstream patch: https://github.com/uclouvain/openjpeg/commit/46c1eff9e98bbcf794d042f7b2e3d45556e805ce
---
Created openjpeg2 tracking bugs for this issue:
Affects: openstack-rdo [bug 1790859]
---
This issue has been addressed in
2020-09-11
Published