Windows DNS Server Remote Code Execution Vulnerability

Plan PatchCVSS 9.8CVE-2026-69730Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows DNS Server allows an attacker to execute code remotely by sending specially crafted DNS queries over the network. No authentication is required. The vulnerability affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 versions 1607 and 1809. Exploitation is assessed as more likely. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker on your network can crash your DNS server or run arbitrary commands with system privileges by sending specially crafted DNS queries, disrupting name resolution for your entire facility and potentially affecting connected industrial devices that rely on DNS.
Who's at risk
Water utilities and municipal electric providers using Windows Server for DNS infrastructure should prioritize this. Any facility relying on DNS for SCADA, RTU, or HMI name resolution is at risk. Windows Server 2016, 2019, 2022, and 2025 systems running the DNS Server role are affected, as well as Windows 10 systems configured as DNS servers.
How it could be exploited
An attacker sends a malformed DNS query to your Windows DNS server over the network (port 53 UDP/TCP). The vulnerability in DNS packet processing causes a use-after-free memory error, allowing the attacker to execute code with DNS service privileges. No authentication or user interaction is required.
Prerequisites
  • Network access to DNS server port 53 (UDP or TCP)
  • Target must be running one of the affected Windows Server or Windows 10 versions
  • DNS Server role must be installed and operational
remotely exploitableno authentication requiredlow complexitycritical severity (CVSS 9.8)affects critical infrastructure servicesexploitation more likely
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/6
Do now
0/1
WORKAROUNDRestrict network access to DNS server port 53 from untrusted networks using firewall rules; allow only authorized subnets
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later via Windows Update
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later via Windows Update
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later via Windows Update
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later via Windows Update
Long-term hardening
0/1
HARDENINGMove DNS server behind a network appliance or filter that inspects and validates DNS traffic if possible
API: /api/v1/advisories/11306870-5f35-4583-9e33-203518f8ea2d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.