New Search

Windows DNS Server Denial of Service Vulnerability - CVE-2019-0811

oval:org.cisecurity:def:6691

A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries. An attacker who successfully exploited this vulnerability could cause the DNS Server service to become nonresponsive. To exploit the vulnerability an unauthenticated attacker could send malicious DNS queries to an affected server resulting in a denial of service. However the DNS server must be configured to use DNS Analytical Logging for the attack to succeed. The update addresses the vulnerability by correcting how Windows DNS Server processes DNS queries.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2012 R2
Class:
vulnerability
Reference(s):
  • CVE-2019-0811
  • MSRC-CVE-2019-0811
  • KB4507457
  • KB4507460
  • KB4507469
Product(s):