Windows DNS Server Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-69551Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows DNS service allows an authorized attacker to execute arbitrary code on vulnerable Windows DNS servers over the network. Affected systems include Windows Server 2016, 2019, 2022, 2025, and Windows 10 (versions 1607 and 1809). Microsoft has released security patches for all affected product lines.
What this means
What could happen
An authorized attacker with network access to a Windows DNS server could execute arbitrary code on the server, potentially disrupting DNS resolution for your entire network or allowing lateral movement into connected systems.
Who's at risk
Windows DNS server administrators and IT teams running Windows Server 2016, 2019, 2022, or 2025 should prioritize this. Any organization relying on Windows DNS for network name resolution is affected, including utilities, municipalities, and other critical infrastructure. Windows 10 systems acting as secondary DNS servers are also vulnerable.
How it could be exploited
An attacker with valid credentials could send a specially crafted network request to the DNS service on a vulnerable Windows Server. The use-after-free vulnerability in the DNS handler would allow the attacker's code to run with DNS service privileges, bypassing normal application boundaries.
Prerequisites
- Valid user credentials on the domain or network
- Network access to port 53 (DNS service)
- Target must be running a vulnerable build of Windows Server 2016, 2019, 2022, 2025 or Windows 10
remotely exploitablerequires valid credentialslow complexityaffects DNS infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/6
Do now
0/1WORKAROUNDRestrict DNS server network access to authorized clients only using firewall rules on port 53
Schedule — requires maintenance window
0/5Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later
All products
HOTFIXUpdate Windows 10 systems to the latest patched builds (1607: 10.0.14393.9512 or later; 1809: 10.0.17763.9245 or later)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/4a6f8d29-d50a-4268-8fa0-f9752d5cfd86Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.