Windows DNS Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-62817Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds write vulnerability in Windows DNS Server allows an unauthorized attacker on an adjacent network to execute arbitrary code. The vulnerability affects Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2019, 2022, and 2025. Microsoft has released patches addressing this issue across all affected versions.

What this means
What could happen
An attacker on an adjacent network could execute arbitrary code on your Windows servers running DNS, potentially compromising the entire network's ability to resolve domain names or allowing lateral movement to other systems.
Who's at risk
Windows administrators running Windows Server 2019, 2022, 2025, or Windows 10/11 systems that provide DNS services should prioritize patching. This affects any organization using these Windows versions as DNS servers, including municipal utilities, government agencies, and enterprises that rely on Windows-based DNS infrastructure.
How it could be exploited
An attacker would send specially crafted DNS packets to the DNS service on a vulnerable Windows server from the same network segment. The out-of-bounds write in the DNS packet processing would allow the attacker to overwrite memory and execute arbitrary code with the DNS service privileges.
Prerequisites
  • Network access to UDP/TCP port 53 (DNS) from the same adjacent network segment
  • Windows DNS Server running on affected Windows version
  • DNS service actively running
Remotely exploitable from adjacent networkNo authentication requiredLow complexity attackAffects DNS services critical to network operationsHigh CVSS score (8.8)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDIf immediate patching is not possible, restrict DNS port 53 access (UDP and TCP) at the network firewall to only authorized DNS clients and block untrusted adjacent networks
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the August 2026 security update from Microsoft to all affected Windows 10 and Windows Server systems
Long-term hardening
0/1
HARDENINGSegment your network to isolate DNS servers and limit their connectivity to only necessary administrative and client networks
API: /api/v1/advisories/cb062fb3-870a-4ed2-a19b-cf655d27150b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.