ZeroHour

CVE-2026-72987

mass

Use-After-Free RCE in Microsoft Windows DNS Server

CVSS 3.1
8.1 high
EPSS
<1%p49
Published
()
Modified
AI analysis

CVE-2026-72987 is a use-after-free (CWE-416) in the Microsoft Windows DNS server component that allows an unauthorized (unauthenticated) remote attacker to execute code over the network. It is likely triggered by crafted network traffic sent to the vulnerable DNS service, which causes it to reference freed memory, and requires no credentials or user interaction. Successful exploitation yields high-impact code execution on the DNS server (CVSS 3.1: 8.1, with high confidentiality, integrity, and availability impact). Any organization running the Windows DNS Server role — including domain controllers that host DNS — is potentially affected, especially where the service is reachable from untrusted networks. The flaw is not currently known to be exploited: it is not in the CISA KEV catalog, no public proof-of-concept is known, and EPSS estimates only about a 0.6% probability of exploitation within 30 days.

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to all servers running the Windows DNS role as soon as possible, prioritizing DNS servers exposed to the internet or to untrusted networks. Until patched, restrict access to TCP/UDP 53 from untrusted sources where feasible and monitor DNS servers for anomalous activity. Consult the Microsoft advisory for the exact affected builds and corresponding KB updates for your Windows versions.

Affected
Microsoft Windows DNS (DNS Server role in Windows)
Estimated exposure
mass≈100,000+ internet-exposed Windows DNS servers; total Windows DNS deployments likely in the millions (DNS role is standard on AD domain controllers) — Public internet-wide scans of TCP/UDP 53 have historically identified on the order of 100,000 or more Windows DNS servers, and the DNS role is installed on nearly every Windows Server domain controller, implying a total installed base in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.