Executive brief
A critical vulnerability has been identified in the Microsoft Windows DNS service, which is responsible for translating human-readable domain names into IP addresses. An attacker can exploit this flaw remotely without any user interaction or login credentials. Successful exploitation could allow an attacker to take complete control of the server, potentially leading to data theft, network-wide disruption, or the deployment of ransomware.
Technical details
This vulnerability is a heap-based buffer overflow (CWE-122) residing within the Microsoft Windows DNS Server component. The flaw is triggered when the service improperly handles specially crafted DNS requests sent over the network. Because the vulnerability is reachable via the network without authentication (AV:N/PR:N) and requires no user interaction (UI:N), it is considered 'wormable' in many environments. An attacker who successfully exploits this vulnerability could run processes with SYSTEM privileges, leading to full machine compromise. Microsoft has released security updates to address this issue; administrators should prioritize patching DNS-capable Windows Server instances.
Affected products
- Microsoft Windows DNS Server
Timeline
- 2026-05-12: advisory: Initial advisory published by Microsoft and NVD.