Windows DNS Server Remote Code Execution Vulnerability
Plan PatchCVSS 9.8CVE-2026-69730Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows DNS Server allows an attacker to execute code remotely by sending specially crafted DNS queries over the network. No authentication is required. The vulnerability affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 versions 1607 and 1809. Exploitation is assessed as more likely. Microsoft has released patches for all affected versions.
What this means
What could happen
An attacker on your network can crash your DNS server or run arbitrary commands with system privileges by sending specially crafted DNS queries, disrupting name resolution for your entire facility and potentially affecting connected industrial devices that rely on DNS.
Who's at risk
Water utilities and municipal electric providers using Windows Server for DNS infrastructure should prioritize this. Any facility relying on DNS for SCADA, RTU, or HMI name resolution is at risk. Windows Server 2016, 2019, 2022, and 2025 systems running the DNS Server role are affected, as well as Windows 10 systems configured as DNS servers.
How it could be exploited
An attacker sends a malformed DNS query to your Windows DNS server over the network (port 53 UDP/TCP). The vulnerability in DNS packet processing causes a use-after-free memory error, allowing the attacker to execute code with DNS service privileges. No authentication or user interaction is required.
Prerequisites
- Network access to DNS server port 53 (UDP or TCP)
- Target must be running one of the affected Windows Server or Windows 10 versions
- DNS Server role must be installed and operational
remotely exploitableno authentication requiredlow complexitycritical severity (CVSS 9.8)affects critical infrastructure servicesexploitation more likely
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/6
Do now
0/1WORKAROUNDRestrict network access to DNS server port 53 from untrusted networks using firewall rules; allow only authorized subnets
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later via Windows Update
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later via Windows Update
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later via Windows Update
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later via Windows Update
Long-term hardening
0/1HARDENINGMove DNS server behind a network appliance or filter that inspects and validates DNS traffic if possible
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/11306870-5f35-4583-9e33-203518f8ea2dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.