Windows DNS Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-69989Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free memory vulnerability exists in Windows DNS Server that allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted network packet to the DNS service. The vulnerability affects Windows 10 (versions 1607 and 1809) and Windows Server 2016, 2019, 2022, and 2025. Microsoft has released security updates for all affected versions.

What this means
What could happen
An attacker could execute arbitrary code on a Windows DNS server without credentials, potentially compromising network services that depend on DNS resolution or affecting systems that rely on this server for name resolution.
Who's at risk
Any organization running Windows DNS servers (Windows Server 2016, 2019, 2022, 2025 or Windows 10) for enterprise or municipal networks. This includes utilities, water authorities, and other critical infrastructure that depend on DNS for network services, SCADA systems communication, and IT infrastructure.
How it could be exploited
An attacker sends a specially crafted network packet to the DNS server port (typically UDP/TCP port 53). The malformed request triggers a use-after-free memory error in the DNS service, allowing the attacker to run code with the privileges of the DNS service.
Prerequisites
  • Network access to DNS server port 53 (UDP and/or TCP)
  • Windows DNS Server service running on an affected version
  • No authentication required
remotely exploitableno authentication requiredhigh CVSS score (8.1)affects critical network servicelow exploit probability but high impact if exploited
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/7
Do now
0/1
WORKAROUNDRestrict network access to DNS port 53 (UDP/TCP) to only authorized DNS clients and servers using firewall rules
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) and Windows Server 2016 to Build 10.0.14393.9512 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.9245 or later
API: /api/v1/advisories/5aeeb55b-a811-49d7-a3c6-b886e29b9ed0

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DNS Server Remote Code Execution Vulnerability | CVSS 8.1 - OTPulse