Skip to content
SigRed (CVE-2020-1350)

SigRed (CVE-2020-1350)

www.tenable.com September 11, 2026

Researchers disclose a 17-year-old wormable flaw in Windows DNS servers. Organizations are strongly encouraged to apply patches as soon as possible.

Update July 17, 2020 : The Proof of Concept and Solutions sections have been updated to reflect the availability of proof of concept scripts and the availability of an audit file for Tenable products.

On July 14, Microsoft patched a critical vulnerability in Windows Domain Name System (DNS) Server as part of Patch Tuesday for July 2020 . The vulnerability was disclosed to Microsoft by Sagi Tzadik and Eyal Itkin, researchers at Check Point Research, who dubbed this vulnerability “SIGRed.” According to the researchers, the vulnerability has persisted in Windows DNS Server for 17 years . Microsoft has published its own blog post the flaw , warning that they consider it wormable.

CVE-2020-1350 is a critical remote code execution (RCE) vulnerability in Windows DNS servers due to the improper handling of DNS requests. It was assigned a CVSSv3 score of 10.0, the highest possible score. To exploit this vulnerability, an attacker would send a malicious request to a vulnerable Windows DNS server. Successful exploitation would grant the attacker arbitrary code execution privileges under the Local System Account context. Microsoft warns that systems at risk include “Windows servers” that have been “configured as DNS servers.”

Second major wormable flaw patched this year

In March of this year, Microsoft released patches for CVE-2020-0796 , a wormable RCE vulnerability in Microsoft Server Message Block 3.1.1, known as EternalDarkness or SMBGhost. While we have yet to see SMBGhost used in a wormable fashion, SIGRed marks the second wormable Microsoft vulnerability patched this year.

SIGRed can be triggered via the browser

Researchers at Check Point found that they could remotely trigger the vulnerability through a web browser. This is achieved by “smuggling” a DNS query in an HTTP request as part of the POST data. However, this vulnerability can only be exploited through browsers that accept HTTP requests over the standard DNS port (53), which include Internet Explorer and Microsoft Edge versions that are not using Chromium .

As part of a demonstration , Check Point Researchers show how they could trigger the vulnerability by sending a link to a user in an email, which when opened would smuggle the DNS query inside of the HTTP request.

At the time this blog post was published, there was no working proof-of-concept (PoC) code available for this vulnerability. However, we have seen at least one fake PoC that RickRolls users. In the past, we’ve also observed some malicious scripts that masquerade as PoCs being published to GitHub. We strongly advise caution when dealing with alleged PoCs.

Since CVE-2020-1350 was made public on July 14, PoCs have been published to GitHub including scripts to apply the mitigation instructions listed in the Solutions section, as well as a few scripts [ 1 , 2 ] that exploit the flaw in order to cause a denial of service.

Microsoft has released patches to address SIGRed across a variety of Windows Server releases. Despite Windows Server 2008 reaching end of life in January 2020 , Microsoft has published security patches to prevent unsupported systems from being compromised by a potential worm.

Tenable strongly encourages organizations to apply these patches as soon as possible.

If applying these patches is not currently feasible, Microsoft provided a workaround via a Windows registry modification:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters DWORD = TcpReceivePacketSize Value = 0xFF00

In order for these changes to take effect, the DNS Service must be restarted.

Microsoft recommends removing the workaround after patches have been applied.

On July 17, our Audit and Compliance team released an audit file for Tenable products that will detect whether or not the mitigation has been applied to assets.

When a target is scanned, it will produce the following result:

If the registry modification has been applied, it will return a “PASSED” value under the compliance tab, otherwise it will return a “FAILED” value.

Identifying affected systems

A list of Tenable plugins to identify this vulnerability will appear here as they’re released.

Microsoft Advisory for CVE-2020-1350

Check Point Research Blog for SIGRed (CVE-2020-1350)

Join Tenable's Security Response Team on the Tenable Community.

Get a free 30-day trial of Tenable.io Vulnerability Management.

The world’s leading AI-powered exposure management platform.

Thank you for your interest in Tenable One. A representative will be in touch soon.

Tenable One Cloud Exposure

Close cloud exposure with the actionable cloud security platform.

Thank you for your interest in Tenable One Cloud Exposure. A representative will be in touch soon.

Tenable Security Center

Identify and prioritize vulnerabilities based on risk to your business. Managed on premises.

Thank you for your interest in Tenable Security Center. A representative will be in touch soon.

Tenable Patch Management

Streamline security and IT collaboration and shorten the mean time to remediate with automation.

Thank you for your interest in Tenable Patch Management. A representative will be in touch soon.

Tenable Enclave Security

Identify, understand and close IT and container vulnerabilities.

Thank you for your interest in Tenable Enclave Security. A representative will be in touch soon.

Tenable One Attack Surface Management

Gain visibility into your internet-connected assets to eliminate blind spots and unknown sources of risk.

Thank you for your interest in Tenable One Attack Surface Management. A representative will be in touch soon.

Tenable One AI Exposure

See, secure, and manage how your teams use AI tools.

Thank you for your interest in Tenable One AI Exposure. A representative will be in touch soon.

Tenable One OT Exposure

Close OT exposure with the unified security solution for converged OT/IT environments.

Thank you for your interest in Tenable One OT Exposure. A representative will be in touch soon.

See Tenable in action

Want to see how Tenable can help your team find and fix critical cyber weaknesses that put your business at risk? Complete this form to get a custom quote or demo.

You should receive a confirmation email shortly and one of our representatives will be in touch.

Learn How Tenable Helps Achieve SLCGP Cybersecurity Plan Requirements

You should receive a confirmation email shortly and one of our Sales Development Representatives will be in touch. Route any questions to [email protected] .

Tenable One Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable One Vulnerability Management trial also includes Tenable One Web App Scanning.

Tenable One Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

Please us or a Tenable partner.

Thank you for your interest in Tenable One Vulnerability Management. A representative will be in touch soon.

Try Tenable One Web App Scanning

Your Tenable One Web App Scanning trial also includes Tenable One Vulnerability Management.

Buy Tenable One Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

Please us or a Tenable partner.

Thank you for your interest in Tenable Web App Scanning. A representative will be in touch soon.

Try Tenable Nessus Professional free

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Fill out the form below to continue with a Nessus Pro trial.

Buy Tenable Nessus Professional

Buy a multi-year license and save. Add Advanced Support for access to phone, community, and chat support 24 hours a day, 365 days a year.

Try Tenable Nessus Expert free

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional? Upgrade to Nessus Expert free for 7 days.

With Advanced Support for Nessus Pro, your teams will have access to phone, Community, and chat support 24 hours a day, 365 days a year. This advanced level of technical support helps to ensure faster response times and resolution to your questions and issues.

Advanced Support Plan Features

Phone support 24 hours a day, 365 days a year, available for up to ten (10) named support contacts.

Chat support available to named support contacts, accessible via the Tenable Community is available 24 hours a day, 365 days a year.

Tenable Community Support Portal

All named support contacts can open support cases within the Tenable Community. Users can also access the Knowledge Base, documentation, license information, technical support numbers, etc.; utilize live chat, ask questions to the Community, and learn tips and tricks from other Community members.

Initial Response Time

P1-Critical: < 2 hr P2-High: < 4 hr P3-Medium: < 12 hr P4-Informational: < 24 hr

Support contacts must be reasonably proficient in the use of information technology, the software they have purchased from Tenable, and familiar with the customer resources that are monitored by means of the software. Support contacts must speak English and conduct support requests in English. Support contacts must provide information reasonably requested by Tenable for the purpose of reproducing any Error or otherwise resolving a support request.

Extracted Entities

Attack Types (1)

Platforms (1)

Vulnerabilities (3)