Windows DNS Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-69827Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A race condition in the Windows DNS Server allows an unauthorized attacker to execute code over the network. The vulnerability exists in all versions of Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 versions 1607 and 1809. Microsoft has released security patches for all affected systems. Exploitation is currently assessed as unlikely, but the vulnerability has a high CVSS score of 8.1 due to the potential for remote code execution without authentication.

What this means
What could happen
An attacker on your network could run arbitrary code on a Windows DNS server, potentially disrupting name resolution for the entire facility or compromising other systems that rely on DNS services.
Who's at risk
Organizations running Windows DNS servers, including those deployed on Windows Server 2016, 2019, 2022, or 2025, as well as Windows 10 systems configured with DNS server roles. This affects any facility using Windows-based DNS infrastructure for network name resolution services.
How it could be exploited
An attacker sends specially crafted DNS requests to a vulnerable Windows DNS server. A race condition in the DNS service allows the attacker to execute arbitrary code with the privileges of the DNS service, which typically runs as a system service.
Prerequisites
  • Network access to port 53 (DNS) on the affected Windows Server
  • The DNS service must be running and exposed to the attacker's network segment
remotely exploitableno authentication requiredaffects critical network servicehigh CVSS score
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDIf immediate patching is not possible, restrict network access to DNS port 53 to only authorized client networks using Windows Firewall or network-layer access controls
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft security update 2026-Sep to all affected Windows Server and Windows 10 systems running DNS services
Long-term hardening
0/1
HARDENINGSegment DNS servers onto a separate, protected network from operational technology systems to limit blast radius if compromise occurs
API: /api/v1/advisories/25970f24-eb71-4280-a017-88c652b15190

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DNS Server Remote Code Execution Vulnerability | CVSS 8.1 - OTPulse