Executive brief
Windows DNS Server contains a memory safety vulnerability that allows attackers on the network to remotely execute code with system-level privileges. An attacker can exploit this flaw by sending specially crafted DNS requests to a vulnerable server, leading to potential compromise of the entire domain and access to sensitive business data or systems.
Technical details
The vulnerability is a use-after-free memory error in the Windows DNS service that can be triggered by a remote, unauthenticated attacker over the network. The flaw exists in DNS packet processing and allows an attacker to execute arbitrary code in the context of the DNS service (typically SYSTEM privilege level). No user interaction is required; the attack can be launched by sending malicious DNS network traffic to the vulnerable DNS server on port 53 (UDP/TCP). A patch has been released by Microsoft to fix this vulnerability.
Affected products
- Microsoft Windows DNS Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory