CVE-2026-69310
massUse-After-Free Local Privilege Elevation in Microsoft Windows DNS
A use-after-free flaw (CWE-416) in the Windows DNS component allows an authorized local user to elevate privileges on the affected machine. Triggering it requires an attacker who already holds low-privilege access on a system running the DNS Server role, and the high attack-complexity score in the CVSS vector suggests exploitation likely depends on timing or memory-layout conditions rather than simple input. Successful exploitation grants elevated rights with high impact on confidentiality, integrity, and availability on that host. Affected systems are Windows installations running the Microsoft DNS server — most commonly Active Directory domain controllers and dedicated DNS servers — although the provided data does not specify affected version ranges. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.3% chance of exploitation within 30 days.
What to do: Check the Microsoft Security Response Center advisory for CVE-2026-69310 and apply the corresponding Windows Server security update as soon as it is available, prioritizing domain controllers and internet- or internally-exposed DNS servers. Until patching, restrict interactive and service logon rights on DNS servers and DCs to trusted administrators and monitor DNS server processes for anomalous activity. Despite the low EPSS score, treat this as a priority fix for AD environments because DNS servers are typically domain controllers with high-value local access.
| Microsoft Windows DNS (DNS Server role) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.