Forum Discussion
Critical Remote Code Execution Flaw in Windows DNS Server...
Hi @Regis P,
Thanks for reaching out to us. The plugins you mentioned are linked under the Identifying Affected Systems section under our standard language ("A list of Tenable plugins to identify this vulnerability will appear here as they’re released.") The plugins and audit file we've produced are several ways to identify affected systems or whether or not mitigations are in place. Since there are multiple avenues of detection, we don't currently have a single "one stop shopping" way to flag vulnerable servers. We are continuing to look into other methods of detection. If you'd like to make a formal request for additional plugin coverage, please reach out to our support team so we can have your request documented. -Satnam
Plugin 138600 is identifying unpatched kernel in Windows 2012 servers that are not running DNS server and listing as vulnerable to Windows DNS Server RCE (CVE-2020-1350), is the expected?