CVE-2020-0856
Published: Sep 11, 2020
Modified: Aug 4, 2024
CVSS v3.1
6.5
Description
<p>An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target system.</p> <p>To exploit this condition, an authenticated attacker would need to send a specially crafted request to the AD|DNS service. Note that the information disclosure vulnerability by itself would not be sufficient for an attacker to compromise a system. However, an attacker could combine this vulnerability with additional vulnerabilities to further exploit the system.</p> <p>The update addresses the vulnerability by correcting how Active Directory integrated DNS (ADIDNS) handles objects in memory.</p>
| Vendor | Product | Versions |
|---|---|---|
Microsoft | Windows Server 2019 | affected 10.0.0 - < publication |
Microsoft | Windows Server 2019 (Server Core installation) | affected 10.0.0 - < publication |
Microsoft | Windows Server, version 1909 (Server Core installation) | affected 10.0.0 - < publication |
Microsoft | Windows Server, version 1903 (Server Core installation) | affected 10.0.0 - < publication |
Microsoft | Windows Server version 2004 | affected 10.0.0 - < publication |
Microsoft | Windows Server 2016 | affected 10.0.0 - < publication |
Microsoft | Windows Server 2016 (Server Core installation) | affected 10.0.0 - < publication |
Microsoft | Windows Server 2008 Service Pack 2 | affected 6.0.0 - < publication |
Microsoft | Windows Server 2008 Service Pack 2 (Server Core installation) | affected 6.0.0 - < publication |
Microsoft | Windows Server 2008 Service Pack 2 | affected 6.0.0 - < publication |
Microsoft | Windows Server 2008 R2 Service Pack 1 | affected 6.1.0 - < publication |
Microsoft | Windows Server 2008 R2 Service Pack 1 (Server Core installation) | affected 6.0.0 - < publication |
Microsoft | Windows Server 2012 | affected 6.2.0 - < publication |
Microsoft | Windows Server 2012 (Server Core installation) | affected 6.2.0 - < publication |
Microsoft | Windows Server 2012 R2 | affected 6.3.0 - < publication |
Microsoft | Windows Server 2012 R2 (Server Core installation) | affected 6.3.0 - < publication |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now