ZeroHour

CVE-2026-69813

mass

Use-after-free RCE in Microsoft Windows DNS Server

CVSS 3.1
8.1 high
EPSS
<1%p50
Published
()
Modified
AI analysis

CVE-2026-69813 is a use-after-free (CWE-416) memory corruption flaw in the Microsoft Windows DNS Server component that allows an unauthorized (unauthenticated) attacker to execute code over a network. An attacker triggers it by sending crafted DNS traffic to a system running the Windows DNS Server role; per the CVSS vector, the attack requires no privileges or user interaction, but the high attack-complexity rating suggests reliable exploitation may depend on favorable memory conditions rather than a trivially repeatable trigger. Successful exploitation yields remote code execution with the privileges of the DNS service — typically a highly privileged account on Windows Server, often on domain controllers, so compromise of an exposed or internal DNS server can be a foothold into the wider Windows environment. All Windows Server deployments with the DNS Server role enabled are in scope, with internet-facing DNS servers and domain controllers the most exposed; the exact affected version ranges are not provided in the available data and should be taken from Microsoft's advisory. There is no evidence of in-the-wild exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at a modest 0.7% (50th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69813 as soon as practical, prioritizing internet-facing DNS servers and domain controllers. In the interim, restrict exposure of UDP/TCP 53 to trusted resolvers where full DNS service is not required externally. Inventory systems running the DNS Server role (e.g., servers listening on port 53) to confirm patch coverage, and watch for a Microsoft advisory note on any attack-complexity-related preconditions or mitigations.

Affected
Microsoft Windows DNS Server (DNS Server role on Windows Server)
Estimated exposure
masshundreds of thousands of systems with the Windows DNS Server role (millions installed; DNS is standard on domain controllers and on most Windows Servers) — The Windows DNS Server role is deployed by default on essentially every Active Directory domain controller and is common on other Windows Servers, giving an installed base in the millions, with the directly network-exposed subset on the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.