CVE-2026-72928
massUse-after-free RCE in Microsoft Windows DNS Server
CVE-2026-72928 is a use-after-free (CWE-416) memory-corruption flaw in the Windows DNS service, assigned by Microsoft. An authorized (low-privileged) attacker can trigger it by sending specially crafted requests over the network to a DNS server running the affected software; the high attack-complexity score suggests a race-condition-style trigger that is not trivially reliable. Successful exploitation allows the attacker to execute arbitrary code in the context of the DNS service on the server host. Any organization running the DNS Server role on Windows Server is in scope, with risk concentrated on servers reachable by network clients, such as domain controllers and internet-facing resolvers. There is no known public proof-of-concept, the issue is not yet in CISA's KEV catalog, and EPSS (0.6%) indicates a low near-term probability of exploitation.
What to do: Monitor Microsoft's advisory and apply the released Windows Server security update for this CVE as soon as it is available for your environment. Prioritize patching internet-facing DNS servers and domain controllers that host the DNS role, and review which low-privileged users can reach DNS services (port 53) on those hosts. Until patched, restrict query access where feasible and watch DNS service logs for anomalous request patterns or service crashes.
| Microsoft Windows DNS (DNS Server role in Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.