Windows DNS Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-65789Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows DNS Server allows an unauthenticated attacker to execute arbitrary code remotely via a specially crafted DNS query. The vulnerability affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 Version 1607 and 1809 on both 32-bit and x64-based systems. Microsoft has released security updates for all affected versions. Exploitation is currently assessed as unlikely.

What this means
What could happen
An attacker could remotely execute code on your Windows DNS server without authentication, potentially allowing them to modify DNS records, redirect network traffic, or compromise systems that rely on correct DNS resolution. If your DNS server hosts safety-critical lookups or process control network addresses, this could disrupt operations.
Who's at risk
Any organization running Windows Server 2016, 2019, 2022, or 2025 (including Server Core installations) with the DNS Server role enabled, or Windows 10 systems configured as DNS servers. This affects municipal IT infrastructure, utilities, and any environment where DNS underpins network operations or hosts process control systems.
How it could be exploited
An attacker on the network sends a specially crafted DNS query to your Windows DNS server. The server processes the malicious input, triggering a use-after-free memory error that allows the attacker to execute arbitrary code with DNS service privileges. The attacker could then modify DNS records to redirect critical infrastructure traffic or run commands to compromise dependent systems.
Prerequisites
  • Network access to DNS server port 53 (UDP/TCP)
  • Target must be running an affected Windows Server version with DNS role enabled
  • No authentication or credentials required
Remotely exploitableNo authentication requiredAffects critical network infrastructure (DNS)High CVSS score (8.1)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to DNS server port 53 (UDP and TCP) to only authorized DNS clients and upstream resolvers
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the August 2026 Microsoft security update (or later) to all affected Windows Server and Windows 10 systems running DNS services
Long-term hardening
0/1
HARDENINGImplement network segmentation to limit which systems can reach your DNS server from untrusted networks
API: /api/v1/advisories/c7be50fb-2b75-4ab8-a08f-d7f68200f7a1

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DNS Server Remote Code Execution Vulnerability | CVSS 8.1 - OTPulse