ZeroHour

CVE-2026-69989

mass

Use-after-free RCE in Microsoft Windows DNS Server

CVSS 3.1
8.1 high
EPSS
<1%p52
Published
()
Modified
AI analysis

A use-after-free memory-safety flaw (CWE-416) in Microsoft's DNS Server component — the Windows DNS Server role — allows an unauthenticated, remote attacker to execute code by sending crafted traffic to the DNS service. The high attack-complexity rating (AC:H) indicates exploitation depends on conditions the attacker does not fully control, likely a timing or state race, so reliable remote exploitation is harder than in a typical network RCE. A successful attacker gains code execution in the context of the DNS Server process, which commonly runs with elevated privileges on domain controllers and other Windows Servers. Potentially affected are any organizations running the DNS Server role on Windows Server, particularly where the service is reachable from untrusted networks or co-located on domain controllers. As of the latest data there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.7% probability of exploitation within 30 days.

What to do: Inventory your estate for servers with the DNS Server role (domain controllers are the most common hosts) and apply Microsoft's security update, prioritizing internet-exposed DNS servers and domain controllers. Where full exposure is not required, restrict inbound TCP/UDP port 53 to trusted sources as an interim mitigation. Because there is no known exploitation or public PoC and attack complexity is high, this can be handled within your normal Microsoft patch cadence, but do not defer it indefinitely given the unauthenticated RCE impact.

Affected
Microsoft Windows DNS Server (DNS Server role)
Estimated exposure
masshundreds of thousands of servers plausibly affected (on the order of 10^5 internet-exposed Windows DNS servers per public scans, plus far more reachable only… — Estimate based on the DNS Server role being widely deployed on Windows Server — commonly co-located on Active Directory domain controllers — and public internet scans of port 53 having historically identified on the order of hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.