Executive brief
Windows DNS Server is a core component that resolves domain names to IP addresses for network communication. A use-after-free vulnerability allows an authorized attacker to execute arbitrary code on affected systems over the network, potentially compromising server integrity and enabling lateral movement within an organization.
Technical details
This vulnerability is a use-after-free memory safety issue in the Windows DNS service. The flaw allows an authenticated attacker with network access to trigger code execution through specially crafted DNS requests or operations. The vulnerability requires the attacker to be authorized (authenticated) to the DNS service, limiting the immediate blast radius. Successful exploitation can lead to remote code execution with DNS service privileges. A patch is available from Microsoft's Security Response Center.
Affected products
- Microsoft Windows DNS Server
Timeline
- 2026-09-08: disclosed