Windows DNS Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-69813Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

Use-after-free vulnerability in Windows DNS service allows remote code execution. An unauthorized attacker can send a specially crafted DNS request over the network to execute arbitrary code with DNS service privileges. Affects Windows 10 (versions 1607, 1809) and Windows Server 2016, 2019, 2022, and 2025 (including Server Core installations).

What this means
What could happen
An attacker on your network could execute arbitrary commands on a Windows server running DNS, potentially allowing them to modify DNS records, redirect traffic, or compromise connected systems.
Who's at risk
Windows administrators operating DNS servers on Windows 10 (versions 1607 and 1809) or Windows Server 2016, 2019, 2022, and 2025 should prioritize this update. Critical for utilities that use Windows-based DNS infrastructure for SCADA network name resolution or supervisory systems.
How it could be exploited
An attacker sends a specially crafted DNS request to an exposed Windows DNS server. The malformed packet triggers a use-after-free memory error in the DNS service, allowing the attacker to run code with DNS service privileges.
Prerequisites
  • Network access to port 53 (UDP/TCP) on the affected Windows DNS server
  • Target must be running Windows 10, Windows Server 2016, 2019, 2022, or 2025
remotely exploitableno authentication requiredaffects DNS service which is foundational to network operationsCVSS 8.1 high severity
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to DNS ports (UDP/TCP 53) using firewall rules to only authorized DNS clients and queries
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 Windows security update to all affected Windows 10 and Windows Server systems running DNS services
Long-term hardening
0/1
HARDENINGSegment DNS servers on a dedicated network with restricted access from untrusted networks
API: /api/v1/advisories/93f1ba9a-b561-441a-82ab-642c5332c5b6

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.