Executive brief
Windows DNS is a core network service that translates domain names to IP addresses for millions of devices. A use-after-free vulnerability allows attackers to execute arbitrary code on vulnerable systems over the network without authentication, potentially enabling malware installation, data theft, or lateral movement through corporate networks.
Technical details
A use-after-free vulnerability exists in the Windows DNS service, where memory is accessed after being freed, allowing attackers to corrupt the heap and achieve remote code execution. The vulnerability can be exploited over the network without authentication. An attacker can send specially crafted DNS requests to trigger the flaw and execute arbitrary code with DNS service privileges. The vulnerability affects Windows DNS components and requires a network attack vector. Microsoft has released patches via the Security Update Guide.
Affected products
- Microsoft Windows DNS
Timeline
- 2026-08-11: disclosed