CVE-2026-69551
massUse-After-Free RCE in Windows DNS Server
CVE-2026-69551 is a use-after-free memory-corruption flaw (CWE-416) in Windows DNS that Microsoft rates 8.8 (High) with network attack vector. An authorized attacker — the CVSS vector requires only low privileges, so any account with minimal access that can reach the DNS service over the network — can send crafted requests that trigger the freed-memory condition and execute code. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, on systems running the Windows DNS Server role, which is most commonly deployed on domain controllers and other Windows Servers. All organizations running Windows DNS are potentially affected, though exploitation requires network reachability and low-level authorization, reducing practical risk for DNS servers that are not exposed to untrusted networks. There is currently no known in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates a 0.9% chance of exploitation in the next 30 days (58th percentile).
What to do: Apply the fix from Microsoft's advisory for this CVE as soon as it is available, prioritizing domain controllers and any Windows Servers where the DNS Server role is installed. Restrict network access to the DNS service (TCP/UDP 53 and related management/RPC interfaces) to trusted networks and authenticated hosts, since exploitation requires only low-privileged authorized access. Check whether your DNS servers are reachable from untrusted networks and monitor Microsoft and CISA feeds for updates on active exploitation.
| Microsoft Windows DNS (DNS Server role) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.