ZeroHour

CVE-2026-77505

mass

Use-After-Free RCE in Microsoft DNS Server (Windows Server)

CVSS 3.1
8.1 high
EPSS
<1%p42
Published
()
Modified
AI analysis

A use-after-free flaw (CWE-416) in Microsoft's DNS Server service can be triggered by maliciously crafted requests sent over the network to a host running the DNS Server role, with no authentication or user interaction required, though the CVSS 8.1 score reflects high attack complexity. A successful exploit would let an unauthorized remote attacker execute arbitrary code on the target host with high impact on confidentiality, integrity, and availability. The affected population is organizations running Microsoft's DNS Server component — most commonly Windows Servers and domain controllers that host DNS, including Active Directory-integrated DNS; the available data does not specify affected version ranges. Exploitation status is currently quiet: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days (42nd percentile). Despite the unproven exploitability, the high severity and the critical role DNS servers play make this a patch-on-availability issue for affected environments.

What to do: Inventory all hosts with the DNS Server role enabled (including domain controllers) and prioritize them for patching when Microsoft releases updates addressing CVE-2026-77505, since no patched versions are specified in the available data. Until patched, restrict network access to TCP/UDP 53 to trusted resolvers and clients, limit open recursion, and monitor DNS service logs for anomalous activity. Note that the high attack complexity suggests exploitation is not trivial, but the severity and ubiquity of DNS infrastructure warrant prompt remediation once fixes are available.

Affected
Microsoft DNS Server (DNS Server role in Windows Server)
Estimated exposure
masshundreds of thousands of internet-exposed instances and likely millions installed (DNS Server role is ubiquitous on Windows Servers/domain controllers) — Estimated from the near-universal deployment of the Microsoft DNS Server role on Windows Servers, especially domain controllers providing Active Directory-integrated DNS, and from public internet scans that show very large numbers of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.