Windows DNS Server Remote Code Execution Vulnerability
Plan PatchCVSS 8.1CVE-2026-69813Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
Use-after-free vulnerability in Windows DNS service allows remote code execution. An unauthorized attacker can send a specially crafted DNS request over the network to execute arbitrary code with DNS service privileges. Affects Windows 10 (versions 1607, 1809) and Windows Server 2016, 2019, 2022, and 2025 (including Server Core installations).
What this means
What could happen
An attacker on your network could execute arbitrary commands on a Windows server running DNS, potentially allowing them to modify DNS records, redirect traffic, or compromise connected systems.
Who's at risk
Windows administrators operating DNS servers on Windows 10 (versions 1607 and 1809) or Windows Server 2016, 2019, 2022, and 2025 should prioritize this update. Critical for utilities that use Windows-based DNS infrastructure for SCADA network name resolution or supervisory systems.
How it could be exploited
An attacker sends a specially crafted DNS request to an exposed Windows DNS server. The malformed packet triggers a use-after-free memory error in the DNS service, allowing the attacker to run code with DNS service privileges.
Prerequisites
- Network access to port 53 (UDP/TCP) on the affected Windows DNS server
- Target must be running Windows 10, Windows Server 2016, 2019, 2022, or 2025
remotely exploitableno authentication requiredaffects DNS service which is foundational to network operationsCVSS 8.1 high severity
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to DNS ports (UDP/TCP 53) using firewall rules to only authorized DNS clients and queries
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the September 2026 Windows security update to all affected Windows 10 and Windows Server systems running DNS services
Long-term hardening
0/1HARDENINGSegment DNS servers on a dedicated network with restricted access from untrusted networks
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/93f1ba9a-b561-441a-82ab-642c5332c5b6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.