Security Update for Microsoft Windows DNS to Address Remote Code Execution
technet.microsoft.com
technet.microsoft.com
Yes, it's not a worm. That doesn't mean it's not a big deal for a lot of people, particularly if they've already had a minor compromise by someone waiting for this kind of exploit to escalate.
I will say Windows DNS servers are much more common on LANs, since they're a core part of Active Directory. But on the internet, I'd agree they're uncommon.
1. https://tools.ietf.org/html/rfc6672 2. https://scans.io/study/sonar.fdns 3. https://hdm.io/data/20151121_dname.txt.gz 4. https://twitter.com/Laughing_Mantis/status/67430845437942579...
[0] - https://twitter.com/Laughing_Mantis/status/67429469573696716...