Executive brief
Windows DNS is the name resolution service used in corporate networks and endpoints to translate domain names into IP addresses. An integer overflow vulnerability in this component allows an attacker on the network to cause a denial of service, disrupting DNS lookups and potentially rendering systems unable to access critical services by their domain names.
Technical details
This vulnerability is an integer overflow or wraparound flaw in the Windows DNS service. The vulnerability can be exploited by sending a specially crafted network request to the DNS service, triggering the integer overflow condition. No authentication is required; an attacker on the network can reach and exploit the vulnerable DNS service. Successful exploitation causes a denial of service condition, potentially crashing the DNS service or making it unresponsive. A patch is available from Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory