ZeroHour

CVE-2026-72928

mass

Use-after-free RCE in Microsoft Windows DNS Server

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-72928 is a use-after-free (CWE-416) memory-corruption flaw in the Windows DNS service, assigned by Microsoft. An authorized (low-privileged) attacker can trigger it by sending specially crafted requests over the network to a DNS server running the affected software; the high attack-complexity score suggests a race-condition-style trigger that is not trivially reliable. Successful exploitation allows the attacker to execute arbitrary code in the context of the DNS service on the server host. Any organization running the DNS Server role on Windows Server is in scope, with risk concentrated on servers reachable by network clients, such as domain controllers and internet-facing resolvers. There is no known public proof-of-concept, the issue is not yet in CISA's KEV catalog, and EPSS (0.6%) indicates a low near-term probability of exploitation.

What to do: Monitor Microsoft's advisory and apply the released Windows Server security update for this CVE as soon as it is available for your environment. Prioritize patching internet-facing DNS servers and domain controllers that host the DNS role, and review which low-privileged users can reach DNS services (port 53) on those hosts. Until patched, restrict query access where feasible and watch DNS service logs for anomalous request patterns or service crashes.

Affected
Microsoft Windows DNS (DNS Server role in Windows Server)
Estimated exposure
mass≈ millions of Windows Server installations (DNS Server role is enabled by default on Active Directory domain controllers) — Windows Server is deployed at massive scale in enterprises, and the DNS Server role ships with and is commonly enabled on domain controllers in virtually every Active Directory environment, putting the potential affected installed base in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.