Junglewise Threat Intelligence

CVE-2026-69989: Microsoft DNS Server use-after-free remote code execution

CVE-2026-69989 · Severity: high · CVSS 8.1 · Published 2026-09-08

Executive brief

Microsoft's DNS Server component, which processes domain name resolution requests across corporate networks, contains a use-after-free memory vulnerability. An attacker on the network can exploit this flaw to execute arbitrary code with system privileges, potentially compromising the entire DNS infrastructure and any systems relying on it.

Technical details

A use-after-free vulnerability in Microsoft DNS Server allows an attacker to execute arbitrary code remotely. The vulnerability is triggered through network-based DNS requests that reference memory that has already been freed, leading to memory corruption. No authentication is required to exploit this flaw; an attacker with network access can send specially crafted DNS packets to trigger the vulnerability. Successful exploitation results in remote code execution with the privileges of the DNS Server process.

Affected products

  • Microsoft DNS Server

Timeline

  • 2026-09-08: disclosed

References