Junglewise Threat Intelligence

CVE-2026-72928: Microsoft Windows DNS Server use-after-free remote code execution

CVE-2026-72928 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows DNS Server is Microsoft's domain name system service that resolves hostnames to IP addresses for network communications. A use-after-free vulnerability allows an authenticated attacker to execute arbitrary code remotely on systems running the DNS service, potentially compromising network infrastructure and enabling lateral movement within enterprise environments.

Technical details

A use-after-free vulnerability exists in Microsoft Windows DNS Server that allows an authorized network attacker to execute arbitrary code. The vulnerability requires prior authentication and network access to the DNS service. An attacker can trigger the use-after-free condition by sending specially crafted DNS requests, leading to memory corruption and code execution with the privileges of the DNS service. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows DNS Server

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats