CVE-2026-69813
massUse-after-free RCE in Microsoft Windows DNS Server
CVE-2026-69813 is a use-after-free (CWE-416) memory corruption flaw in the Microsoft Windows DNS Server component that allows an unauthorized (unauthenticated) attacker to execute code over a network. An attacker triggers it by sending crafted DNS traffic to a system running the Windows DNS Server role; per the CVSS vector, the attack requires no privileges or user interaction, but the high attack-complexity rating suggests reliable exploitation may depend on favorable memory conditions rather than a trivially repeatable trigger. Successful exploitation yields remote code execution with the privileges of the DNS service — typically a highly privileged account on Windows Server, often on domain controllers, so compromise of an exposed or internal DNS server can be a foothold into the wider Windows environment. All Windows Server deployments with the DNS Server role enabled are in scope, with internet-facing DNS servers and domain controllers the most exposed; the exact affected version ranges are not provided in the available data and should be taken from Microsoft's advisory. There is no evidence of in-the-wild exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at a modest 0.7% (50th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69813 as soon as practical, prioritizing internet-facing DNS servers and domain controllers. In the interim, restrict exposure of UDP/TCP 53 to trusted resolvers where full DNS service is not required externally. Inventory systems running the DNS Server role (e.g., servers listening on port 53) to confirm patch coverage, and watch for a Microsoft advisory note on any attack-complexity-related preconditions or mitigations.
| Microsoft Windows DNS Server (DNS Server role on Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.