Windows DNS Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-62820Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A race condition in Windows DNS Server allows an unauthenticated attacker to execute arbitrary code via network traffic. The vulnerability affects Windows Server 2016, 2019, 2022, 2025, and Windows 10 versions 1607 and 1809. Successful exploitation could allow an attacker to manipulate DNS responses, redirect traffic, or compromise the DNS server itself.

What this means
What could happen
A remote attacker could execute code on your DNS server, potentially redirecting traffic, poisoning DNS records, or compromising systems that rely on DNS resolution. This could disrupt critical services like SCADA communications or network access.
Who's at risk
Water utilities, electric utilities, and any industrial facility using Windows-based DNS servers for network infrastructure are affected. This includes DNS servers supporting SCADA, HMI, RTU, and other critical control network communications.
How it could be exploited
An attacker sends specially crafted network traffic to the Windows DNS service (port 53). The race condition in DNS request handling allows the attacker to inject and execute arbitrary code without authentication. Exploitation requires precise timing and network access to the DNS server.
Prerequisites
  • Network access to port 53 (UDP/TCP) on the target DNS server
  • Target system must be running an affected version of Windows 10, Windows Server 2016, 2019, 2022, or 2025
remotely exploitableno authentication requiredhigh complexity required for exploitationaffects network infrastructurehigh CVSS score (8.1)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/5
Do now
0/1
WORKAROUNDRestrict network access to DNS port 53 to authorized clients only using Windows Firewall or network ACLs
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9418 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
API: /api/v1/advisories/887af4e1-2566-4f30-bf31-8dab8787e518

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DNS Server Remote Code Execution Vulnerability | CVSS 8.1 - OTPulse