ZeroHour

CVE-2026-78523

mass

Use-After-Free in Windows DNS Enables Unauthenticated DoS

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
AI analysis

Microsoft's Windows DNS component contains a use-after-free vulnerability (CWE-416) that can be triggered remotely by unauthenticated network traffic processed by the DNS service. An attacker who sends crafted DNS requests to a vulnerable system can cause memory corruption that crashes the DNS service, resulting in denial of service; the CVSS vector (availability-only impact, high) indicates no confidentiality or integrity loss and no code execution. Affected products are Windows 10 1607 and 1809 and Windows Server 2012, 2016, 2019, 2022, and 2025, and because Windows domain controllers typically run the DNS Server role, most Active Directory environments are plausibly exposed. As of the latest data there is no known exploitation in the wild (not in CISA KEV), no public proof-of-concept, and EPSS estimates only about a 0.9% probability of exploitation within 30 days (57th percentile).

What to do: Apply the Microsoft security update addressing CVE-2026-78523 to all systems running the DNS Server role when it is released, prioritizing internet-facing DNS servers and domain controllers. Until patched, restrict inbound TCP/UDP 53 at the perimeter to trusted resolvers and clients, and monitor DNS service health and crash events. With no known exploitation and low EPSS, this is routine patching rather than an emergency, but note that a successful attack degrades name resolution org-wide.

Affected
microsoft Windows 101607, 1809 (as listed in the advisory; no granular build ranges provided)
microsoft Windows Server2012, 2016, 2019, 2022, 2025 (as listed in the advisory; no granular build ranges provided)
Estimated exposure
mass≈1M+ installations running the Windows DNS Server role (DNS is near-universal on Windows domain controllers), with tens of thousands directly exposed to the… — Every Active Directory domain requires DNS and Windows Server 2012–2025 remains widely deployed, so the number of systems with the affected DNS role runs into the millions, while internet-wide scans of TCP/UDP 53 show tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.