Microsoft reveals rare 'wormable' bug found in Windows servers - with maximum severity rating

(Image credit: Shutterstock / hywards)

Microsoft has issued a patch for a critical vulnerability found to affect nearly all Windows DNS Server versions.

As confirmed by a blog post from Microsoft Security Response Center, the remote code execution (RCE) flaw is classified as “wormable” for its capacity to let malware spread across the entirety of a corporate network, with crippling effects.

It was handed the maximum severity score of 10.0 by the Common Vulnerability Scoring System (CVSS), highlighting the significant and immediate nature of the threat.

The flaw does not affect Windows 10 nor any other consumer implementation - only Windows DNS Server deployments.

'Wormable' Windows flaw

The Windows DNS Server vulnerability was first identified by security researchers at Check Point, who disclosed their discovery to Microsoft in May.

“A DNS server breach is a very serious thing. There are only a handful of these vulnerability types ever released,” said Omri Herscovici, Research Team Leader at Check Point.

“Every organization big or small using Microsoft infrastructure is at major security risk, if left unpatched. The risk would be a complete breach of the entire corporate network.”

Microsoft has now issued a patch for all Windows DNS Server versions, which system administrators are advised to apply immediately - although it is thought the bug is yet to be exploited in the wild.

“Wormable vulnerabilities have the potential to spread via malware between vulnerable computers without user interaction. Windows DNS Server is a core networking component,” explained Mechele Gruhn of Microsoft Security Response Center.

“While this vulnerability is not currently known to be used in active attacks, it is essential that customers apply Windows updates to address this vulnerability as soon as possible.”

Gruhn goes on to explain that, if circumstances mean an update is impractical, a workaround is available that does not involve restarting the server. Administrators that lean on the automatic updates facility, meanwhile, need take no further action. 

Via The Verge

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does