Executive brief
Windows DNS Server processes domain name resolution requests from across the network. A use-after-free vulnerability allows an unauthenticated attacker to send specially crafted DNS queries that could result in remote code execution, potentially compromising the entire DNS infrastructure and enabling network-wide attacks.
Technical details
A use-after-free vulnerability exists in Windows DNS Server's request handling logic. The vulnerability is triggered by a network-reachable attacker sending crafted DNS queries without requiring authentication or user interaction. Successful exploitation allows arbitrary code execution in the context of the DNS service, potentially leading to full system compromise. A patch is available from Microsoft.
Affected products
- Microsoft Windows DNS Server
Timeline
- 2026-09-08: disclosed