ZeroHour

CVE-2026-69551

mass

Use-After-Free RCE in Windows DNS Server

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-69551 is a use-after-free memory-corruption flaw (CWE-416) in Windows DNS that Microsoft rates 8.8 (High) with network attack vector. An authorized attacker — the CVSS vector requires only low privileges, so any account with minimal access that can reach the DNS service over the network — can send crafted requests that trigger the freed-memory condition and execute code. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, on systems running the Windows DNS Server role, which is most commonly deployed on domain controllers and other Windows Servers. All organizations running Windows DNS are potentially affected, though exploitation requires network reachability and low-level authorization, reducing practical risk for DNS servers that are not exposed to untrusted networks. There is currently no known in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates a 0.9% chance of exploitation in the next 30 days (58th percentile).

What to do: Apply the fix from Microsoft's advisory for this CVE as soon as it is available, prioritizing domain controllers and any Windows Servers where the DNS Server role is installed. Restrict network access to the DNS service (TCP/UDP 53 and related management/RPC interfaces) to trusted networks and authenticated hosts, since exploitation requires only low-privileged authorized access. Check whether your DNS servers are reachable from untrusted networks and monitor Microsoft and CISA feeds for updates on active exploitation.

Affected
Microsoft Windows DNS (DNS Server role)
Estimated exposure
masslikely hundreds of thousands to millions of Windows Server installations with the DNS Server role (most commonly domain controllers); exact count unknown — The DNS Server role is a standard component of nearly all Active Directory deployments, implying a very large installed base worldwide, though the subset that is internet-exposed or reachable by low-privileged attackers is smaller and not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.