CVE-2026-77505
massUse-After-Free RCE in Microsoft DNS Server (Windows Server)
A use-after-free flaw (CWE-416) in Microsoft's DNS Server service can be triggered by maliciously crafted requests sent over the network to a host running the DNS Server role, with no authentication or user interaction required, though the CVSS 8.1 score reflects high attack complexity. A successful exploit would let an unauthorized remote attacker execute arbitrary code on the target host with high impact on confidentiality, integrity, and availability. The affected population is organizations running Microsoft's DNS Server component — most commonly Windows Servers and domain controllers that host DNS, including Active Directory-integrated DNS; the available data does not specify affected version ranges. Exploitation status is currently quiet: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days (42nd percentile). Despite the unproven exploitability, the high severity and the critical role DNS servers play make this a patch-on-availability issue for affected environments.
What to do: Inventory all hosts with the DNS Server role enabled (including domain controllers) and prioritize them for patching when Microsoft releases updates addressing CVE-2026-77505, since no patched versions are specified in the available data. Until patched, restrict network access to TCP/UDP 53 to trusted resolvers and clients, limit open recursion, and monitor DNS service logs for anomalous activity. Note that the high attack complexity suggests exploitation is not trivial, but the severity and ubiquity of DNS infrastructure warrant prompt remediation once fixes are available.
| Microsoft DNS Server (DNS Server role in Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.