CVE-2021-26894HighCVSS 9.8

Windows DNS Server Remote Code Execution Vulnerability

Published
March 9, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

If my server is not configured to be a DNS server, it is vulnerable? No, this vulnerability is only exploitable if the server is configured to be a DNS server.

Can this vulnerability by mitigated by enabling Secure Zone Updates? Enabling Secure Zone Updates constrains the potential sources of the attack, but does not completely prevent it. For example, a malicious insider could attack a “secure zone update” DNS server from a domain-joined computer. This is only a partial mitigation. Does this vulnerability impact just standalone DNS Primary Authoritative Server and not a DNS Server integrated with Active Directory? This vulnerability impacts any DNS server. The surrounding configuration can limit possible vectors/sources for the attack, but proper mitigation requires this month’s security update patch.

🎯 Affected products17

  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for x64-based Systems Service Pack 2
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server, version 1909 (Server Core installation)
  • Windows Server, version 2004 (Server Core installation)
  • Windows Server, version 20H2 (Server Core Installation)

✅ Remediation

KB5000822 (Security Update) — fixed build 10.0.17763.1817 KB5000808 (Security Update) — fixed build 10.0.18363.1440 KB5000802 (Security Update) — fixed build 10.0.19043.867 KB5000803 (Security Update) — fixed build 10.0.14393.4283 KB5000844 (Monthly Rollup) — fixed build 6.0.6003.21070 KB5000856 (Security Only) KB5000841 (Monthly Rollup) — fixed build 6.1.7601.24566 KB5000851 (Security Only) KB5000847 (Monthly Rollup) — fixed build 6.2.9200.23298 KB5000840 (Security Only) KB5000848 (Monthly Rollup) — fixed build 6.3.9600.19968 KB5000853 (Security Only)

🔗 References (25)