CVE-2026-69631
massUnauthenticated Integer Overflow DoS in Microsoft Windows DNS
CVE-2026-69631 is an integer overflow or wraparound flaw (CWE-190) in the Microsoft Windows DNS component, where a value computed by the DNS service can exceed its bounds and wrap, leaving the service in a failed state. A remote, unauthenticated attacker can trigger it by sending crafted network traffic to a system running the affected DNS service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no credentials or user interaction are required. The confirmed impact is denial of service only (C:N/I:N/A:H, CVSS 7.5): no data theft or tampering, but a successful attack can crash or hang DNS resolution, which on domain controllers or primary resolvers can disrupt name resolution for an entire site. Anyone running the affected Windows DNS component is in scope; Microsoft (the assigned CNA) has not published a version range in the data provided, so defenders should check the MSRC advisory for the affected edition list. Exploitation status: not in CISA KEV, no public PoC, and EPSS estimates a 1.2% probability of exploitation within 30 days (66th percentile), so no confirmed in-the-wild activity is known.
What to do: Track the MSRC advisory for CVE-2026-69631 and deploy the security update Microsoft publishes, prioritizing internet-exposed DNS servers and domain controllers. Until patched, restrict port 53 exposure to trusted networks, disable or limit open recursion, and enable DNS query rate-limiting where available. Inventory your estate for systems running the Windows DNS Server role to scope patching.
| Microsoft Windows DNS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.