Windows DNS Server Remote Code Execution Vulnerability
Plan PatchCVSS 9.8CVE-2026-62878Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Stack-based buffer overflow in Windows DNS Server allows an unauthorized attacker to execute code over a network via a specially crafted DNS query. Affects Windows 10 (versions 1607, 1809) and Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
A stack-based buffer overflow in Windows DNS Server could allow an attacker on your network to execute arbitrary code with system privileges, potentially taking control of your DNS infrastructure and enabling further attacks on your systems.
Who's at risk
Water authorities and electric utilities operating Windows DNS Servers for network name resolution, including those running Windows Server 2016, 2019, 2022, or 2025, or Windows 10 systems in DNS-serving roles. This affects any organization that relies on Windows DNS for SCADA system communication, RTU addressing, or general network infrastructure.
How it could be exploited
An attacker sends a specially crafted DNS query to a Windows DNS Server over the network. The malformed query triggers a buffer overflow in the DNS processing code, allowing the attacker to overwrite the stack and inject executable code that runs with SYSTEM privileges.
Prerequisites
- Network access to the Windows DNS Server on port 53 (TCP or UDP)
- No authentication or credentials required
- Windows DNS Server role enabled on the target
Remotely exploitableNo authentication requiredLow complexity attackCVSS 9.8 (critical)Affects DNS infrastructure used for ICS communication
Exploitability
Some exploitation risk — EPSS score 1.3%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to DNS servers on port 53 (TCP/UDP) to only authorized clients and networks using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's August 2026 security update to all affected Windows Server and Windows 10 systems running DNS services
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate DNS servers from untrusted networks and limit the scope of potential compromise
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b725e44f-7e65-4684-be36-e8041c4c1755Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.