ZeroHour

CVE-2026-69631

mass

Unauthenticated Integer Overflow DoS in Microsoft Windows DNS

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
AI analysis

CVE-2026-69631 is an integer overflow or wraparound flaw (CWE-190) in the Microsoft Windows DNS component, where a value computed by the DNS service can exceed its bounds and wrap, leaving the service in a failed state. A remote, unauthenticated attacker can trigger it by sending crafted network traffic to a system running the affected DNS service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no credentials or user interaction are required. The confirmed impact is denial of service only (C:N/I:N/A:H, CVSS 7.5): no data theft or tampering, but a successful attack can crash or hang DNS resolution, which on domain controllers or primary resolvers can disrupt name resolution for an entire site. Anyone running the affected Windows DNS component is in scope; Microsoft (the assigned CNA) has not published a version range in the data provided, so defenders should check the MSRC advisory for the affected edition list. Exploitation status: not in CISA KEV, no public PoC, and EPSS estimates a 1.2% probability of exploitation within 30 days (66th percentile), so no confirmed in-the-wild activity is known.

What to do: Track the MSRC advisory for CVE-2026-69631 and deploy the security update Microsoft publishes, prioritizing internet-exposed DNS servers and domain controllers. Until patched, restrict port 53 exposure to trusted networks, disable or limit open recursion, and enable DNS query rate-limiting where available. Inventory your estate for systems running the Windows DNS Server role to scope patching.

Affected
Microsoft Windows DNS
Estimated exposure
mass~1M+ deployments (roughly 700k+ internet-exposed Windows DNS servers in past public scans, plus DNS-on-domain-controller ubiquity) — Public internet scans during earlier Windows DNS vulnerabilities counted on the order of 700,000 internet-exposed Windows DNS servers, and the DNS Server role is installed on most Active Directory domain controllers inside organizations,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network.

Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.