Windows DNS Server Remote Code Execution Vulnerability
Plan PatchCVSS 8.1CVE-2026-69782Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
A race condition in Windows DNS Server allows remote code execution. An attacker can exploit improper synchronization in concurrent execution of shared resources to execute arbitrary code over the network.
What this means
What could happen
An attacker could run arbitrary code on your DNS server, potentially disrupting name resolution for your entire network and allowing redirection of traffic to malicious systems. This could impact all systems that rely on DNS, including SCADA networks and process automation systems.
Who's at risk
Organizations running Windows Server 2016, 2019, 2022, or 2025 as a DNS server. This affects any facility relying on Windows DNS for network name resolution, including water authorities and utilities with SCADA systems, HMIs, and control networks that depend on DNS for communication.
How it could be exploited
An attacker sends specially crafted DNS requests to your DNS server over the network. The race condition allows the attacker to trigger concurrent execution of shared resources in an unsafe way, leading to code execution on the DNS server with system privileges.
Prerequisites
- Network access to DNS server port 53 (UDP or TCP)
- DNS Server role installed and running on the target Windows system
remotely exploitableno authentication requiredaffects critical infrastructure (DNS)high CVSS score (8.1)
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/5
Do now
0/1WORKAROUNDRestrict network access to DNS server port 53 (UDP/TCP) to only authorized clients and name servers
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/d3c37619-24cb-407f-bcdd-838833362a56Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.