Windows DNS Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-69858Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows DNS Server allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted network request over port 53. Affected versions include Windows Server 2022 and Windows Server 2025 (both full and Server Core installations). Exploitation is assessed as unlikely but possible.

What this means
What could happen
An attacker could execute arbitrary code on your DNS server by sending a specially crafted network request, potentially compromising DNS resolution for your entire facility network or modifying DNS responses to redirect traffic to attacker-controlled systems.
Who's at risk
Windows Server 2022 and Windows Server 2025 systems running DNS services. This affects any utility that relies on Windows DNS servers for name resolution, including SCADA systems, HMIs, and networked industrial equipment that depend on DNS for communication.
How it could be exploited
An attacker on the network sends a malformed DNS query that triggers a use-after-free condition in the Windows DNS service, allowing arbitrary code execution without authentication or user interaction.
Prerequisites
  • Network access to port 53 (DNS) on the Windows DNS server
  • No authentication required
  • Attacker must craft a specific DNS packet; exploitation requires network-level access
Remotely exploitableNo authentication requiredHigh CVSS score (8.1)Affects DNS infrastructure critical to operations
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/2
Do now
0/1
WORKAROUNDRestrict network access to port 53 (DNS) to only authorized clients and internal network segments; deny inbound DNS queries from untrusted external networks
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Sep Windows security update (Build 10.0.20348.5622 for Server 2022 or Build 10.0.26100.33438 for Server 2025) to all affected Windows DNS servers
API: /api/v1/advisories/8a040868-485b-42fa-92d7-8592332e5b86

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DNS Server Remote Code Execution Vulnerability | CVSS 8.1 - OTPulse