Windows DNS Server Remote Code Execution Vulnerability

Plan PatchCVSS 8CVE-2026-49169Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityHigh
User InteractionNone needed
Summary

Use-after-free vulnerability in Windows Server 2025 DNS Server allows an authorized attacker with administrative or DNS management credentials to execute arbitrary code on the DNS server over the network. The vulnerability requires high privilege access and specialized crafted requests, making exploitation less likely but potentially high-impact if successful.

What this means
What could happen
An attacker with administrative or DNS management credentials could exploit a use-after-free flaw in Windows DNS Server to run arbitrary code on your DNS server, potentially disrupting name resolution across your network or compromising other systems that rely on DNS.
Who's at risk
Organizations running Windows Server 2025 (both full and Server Core installations) as DNS servers. This affects any environment where DNS services are critical to network operations, including IT networks that support industrial control systems or SCADA environments.
How it could be exploited
An attacker must first obtain elevated credentials (administrative or DNS management access) on the Windows DNS Server. They then send a specially crafted DNS request over the network that triggers the use-after-free condition, allowing code execution in the DNS Server process.
Prerequisites
  • Administrative or DNS management credentials on the DNS server
  • Network access to the DNS Server (typically port 53 for DNS queries)
  • Ability to send specially crafted DNS requests
remotely exploitablehigh privilege requirementsaffects network critical servicesuse-after-free memory vulnerability
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXUpdate Windows Server 2025 systems to Build 10.0.26100.33158 or later using the 2026-Jul security update
Long-term hardening
0/2
HARDENINGRestrict network access to DNS port 53 to only authorized DNS clients and secondary DNS servers
HARDENINGLimit DNS management credentials and administrative access to only personnel who require it
API: /api/v1/advisories/1485187c-7469-449c-8395-45b76564eb8c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DNS Server Remote Code Execution Vulnerability | CVSS 8 - OTPulse