Junglewise Threat Intelligence

CVE-2026-70091: Microsoft Windows DNS race condition denial of service

CVE-2026-70091 · Severity: medium · CVSS 5.9 · Published 2026-09-08

Executive brief

Windows DNS Server is a critical network service that resolves domain names to IP addresses for organizations. A race condition in DNS processing allows an unauthorized attacker to crash the DNS service over a network, disrupting name resolution and potentially affecting all network communication that depends on DNS lookups.

Technical details

This vulnerability is a race condition in Windows DNS Server caused by improper synchronization when multiple threads access shared resources. An unauthenticated attacker on the network can send crafted DNS requests that trigger the race condition, leading to service termination or crash. The vulnerability requires network connectivity to the DNS server but no authentication or special privileges. An exploit allows denial of service (service unavailability), preventing the DNS server from resolving names for network clients. Patches are expected to be available through Windows security updates.

Affected products

  • Microsoft Windows DNS Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats