DHS CISA issued an emergency directive yesterday, ordering all U.S. to deploy patches or mitigations for a critical bug in Windows Server DNS within 24 hours. The emergency directive calls on the country’s government agencies to fix a bug known as SIGRed, which was discovered by researchers at Check Point. Microsoft released updates for the bug earlier this week.

The bug affects the DNS server component that ships with all versions of Windows Server from 2003 to 2019. SIGRed can be exploited to execute malicious code on a Windows Server that has the DNS server component enabled. Microsoft says that this bug can be used for self-replicating attacks that spread across the Internet or even organizations.
In a press release released yesterday, CISA Director Christopher Krebs said the bug is of particular interest to DHS, the US agency responsible for overseeing the security of the US government's computer networks. He urged government agencies to patch servers as soon as possible, and asked the private sector to do the same.

In addition, CISA cited the potential for exploitation of the “SIGRed” bug, the widespread use of the affected software across the federal government network, the high risk of breaching service information systems , and the serious impact that a successful breach, in justifying its move to issue an emergency directive, given that this is a form of notification issued in extremely rare cases.

Emergency Directive ED 20-03 required U.S. organizations to install the security released by Microsoft within 24 hours, which is now Friday, July 17, 2020, at 2:00 PM EDT, if they are running Windows Server instances with the DNS role. If the security updates cannot be installed, CISA requires organizations to deploy a registry modification workaround detailed in the Microsoft SIGRed advisory (CVE-2020-1350). Organizations then have another week to remove the workaround and apply the security update. Servers that cannot be updated should be removed from an organization’s network, according to CISA.
The bug, identified as CVE-2020-1350, is one of several bugs disclosed this month, receiving a severity rating of 10/10 on the CVSSv3 severity scale. Other similarly dangerous bugs that are easy to exploit over the Internet include bugs in Palo Alto Networks' PAN-OS operating system, F5's BIG-IP networking appliances, and several SAP cloud applications
