Executive brief
Windows DNS Server is Microsoft's domain name system service that resolves hostnames to IP addresses for network communications. A use-after-free vulnerability allows an authenticated attacker to execute arbitrary code remotely on systems running the DNS service, potentially compromising network infrastructure and enabling lateral movement within enterprise environments.
Technical details
A use-after-free vulnerability exists in Microsoft Windows DNS Server that allows an authorized network attacker to execute arbitrary code. The vulnerability requires prior authentication and network access to the DNS service. An attacker can trigger the use-after-free condition by sending specially crafted DNS requests, leading to memory corruption and code execution with the privileges of the DNS service. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows DNS Server
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory