ZeroHour

CVE-2026-69858

mass

Use-After-Free Remote Code Execution in Windows DNS Server

CVSS 3.1
8.1 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-69858 is a use-after-free memory-corruption flaw (CWE-416) in the Windows DNS Server component, addressed by Microsoft in the September 2026 Patch Tuesday release. An unauthorized remote attacker who can send crafted DNS traffic to an affected Windows DNS server can trigger the flaw, in which memory is freed while still in use, potentially corrupting it. Successful exploitation yields arbitrary code execution on the DNS server, though the network-accessible attack carries High attack complexity (CVSS 3.1 8.1, AV:N/AC:H/PR:N/UI:N), indicating reliable exploitation is harder to achieve. Affected are any organizations running the DNS Server role on Windows Server, which is nearly universal on Active Directory domain controllers and common on standalone and internet-facing DNS servers. As of the available data there is no public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.7% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is known.

What to do: Apply the September 2026 Microsoft security updates for Windows DNS Server as soon as your release channel provides them, prioritizing domain controllers and any DNS servers reachable from untrusted networks or the internet. Inventory servers with the DNS Server role (e.g., check for the DNS Server feature/role) and verify patch status after deployment. As an interim mitigation, restrict untrusted network access to DNS service ports (TCP/UDP 53) where feasible.

Affected
Microsoft Windows DNS Server (DNS Server role on Windows Server)
Estimated exposure
masson the order of millions of installations with the DNS Server role (most domain controllers), of which tens of thousands are internet-exposed — The DNS Server role ships on the vast majority of Windows Server/Active Directory deployments (an installed base measured in the millions), while public internet scans typically show tens of thousands of Windows DNS servers reachable on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.