CVE-2020-1228: Microsoft Windows Server 2008

High severity, CVSS 7.5. EPSS: 4.5% chance of exploitation in the next 30 days.

<p>A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.</p> <p>To exploit the vulnerability, an authenticated attacker could send malicious DNS queries to a target, resulting in a denial of service.</p> <p>The update addresses the vulnerability by correcting how Windows DNS processes queries.</p>

Affected products

  • Microsoft Windows Server 2008: affected versions not specified; version r2 only
  • Microsoft Windows Server 2012: affected versions not specified; version r2 only
  • Microsoft Windows Server 2016: affected versions not specified; version 1903 only; version 1909 only; version 2004 only
  • Microsoft Windows Server 2019: affected versions not specified

Published 2020-09-11. Last modified 2026-06-17.