CVE-2026-69989
massUse-after-free RCE in Microsoft Windows DNS Server
A use-after-free memory-safety flaw (CWE-416) in Microsoft's DNS Server component — the Windows DNS Server role — allows an unauthenticated, remote attacker to execute code by sending crafted traffic to the DNS service. The high attack-complexity rating (AC:H) indicates exploitation depends on conditions the attacker does not fully control, likely a timing or state race, so reliable remote exploitation is harder than in a typical network RCE. A successful attacker gains code execution in the context of the DNS Server process, which commonly runs with elevated privileges on domain controllers and other Windows Servers. Potentially affected are any organizations running the DNS Server role on Windows Server, particularly where the service is reachable from untrusted networks or co-located on domain controllers. As of the latest data there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.7% probability of exploitation within 30 days.
What to do: Inventory your estate for servers with the DNS Server role (domain controllers are the most common hosts) and apply Microsoft's security update, prioritizing internet-exposed DNS servers and domain controllers. Where full exposure is not required, restrict inbound TCP/UDP port 53 to trusted sources as an interim mitigation. Because there is no known exploitation or public PoC and attack complexity is high, this can be handled within your normal Microsoft patch cadence, but do not defer it indefinitely given the unauthenticated RCE impact.
| Microsoft Windows DNS Server (DNS Server role) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.