CVE-2026-78523
massUse-After-Free in Windows DNS Enables Unauthenticated DoS
Microsoft's Windows DNS component contains a use-after-free vulnerability (CWE-416) that can be triggered remotely by unauthenticated network traffic processed by the DNS service. An attacker who sends crafted DNS requests to a vulnerable system can cause memory corruption that crashes the DNS service, resulting in denial of service; the CVSS vector (availability-only impact, high) indicates no confidentiality or integrity loss and no code execution. Affected products are Windows 10 1607 and 1809 and Windows Server 2012, 2016, 2019, 2022, and 2025, and because Windows domain controllers typically run the DNS Server role, most Active Directory environments are plausibly exposed. As of the latest data there is no known exploitation in the wild (not in CISA KEV), no public proof-of-concept, and EPSS estimates only about a 0.9% probability of exploitation within 30 days (57th percentile).
What to do: Apply the Microsoft security update addressing CVE-2026-78523 to all systems running the DNS Server role when it is released, prioritizing internet-facing DNS servers and domain controllers. Until patched, restrict inbound TCP/UDP 53 at the perimeter to trusted resolvers and clients, and monitor DNS service health and crash events. With no known exploitation and low EPSS, this is routine patching rather than an emergency, but note that a successful attack degrades name resolution org-wide.
| microsoft Windows 10 | 1607, 1809 (as listed in the advisory; no granular build ranges provided) |
| microsoft Windows Server | 2012, 2016, 2019, 2022, 2025 (as listed in the advisory; no granular build ranges provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.