Executive brief
Windows DNS Server contains a use-after-free vulnerability that allows an unauthenticated attacker to execute arbitrary code remotely. This affects the DNS service which is critical infrastructure in most Windows network environments. Exploitation could lead to complete server compromise and lateral movement throughout an organization's network.
Technical details
A use-after-free vulnerability exists in Windows DNS Server's memory management. The vulnerability can be triggered remotely over the network without authentication or user interaction required. An attacker can craft malicious DNS requests to trigger the use-after-free condition, leading to remote code execution with the privileges of the DNS service. The attack vector is network-based, affecting DNS servers that are directly reachable or accessible to the attacker. Patches are available from Microsoft.
Affected products
- Microsoft Windows DNS Server
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory