Executive brief
Windows DNS Server contains a use-after-free vulnerability that allows an unauthenticated attacker to execute arbitrary code remotely over the network. Successful exploitation could compromise DNS infrastructure, enabling attackers to redirect network traffic, intercept communications, or establish persistent footholds in corporate environments that rely on DNS services for critical operations.
Technical details
A use-after-free vulnerability exists in the Windows DNS Server component, where freed memory is accessed after deallocation, potentially allowing arbitrary code execution. The vulnerability is remotely exploitable over the network without requiring authentication or user interaction. An unauthenticated attacker can send specially crafted DNS protocol packets to trigger the flaw and execute code with DNS Server privileges. No public exploits are currently known to be in active use, though the high CVSS score (8.1) reflects the severity of the exposure.
Affected products
- Microsoft Windows DNS Server
Timeline
- 2026-09-08: disclosed