article thumbnail

One Year Later: What Can We Learn from Zerologon?

Tenable

CVE-2020-1350: Wormable Remote Code Execution Vulnerability in Windows DNS Server Disclosed (SIGRed). CVE-2020-2040: Critical Buffer Overflow Vulnerability in PAN-OS Devices Disclosed. Because this is a local privilege escalation flaw, an attacker needs to be on the same local area network (LAN) as their target. September 2.