Windows DNS Server Remote Code Execution Vulnerability
Plan PatchCVSS 7.5CVE-2026-72928Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
Use-after-free vulnerability in Windows DNS Server allows an authorized attacker to execute arbitrary code over the network. Affects Windows Server 2025 in both standard and Server Core installations. Exploitation is considered unlikely, but a patch is available.
What this means
What could happen
An authenticated attacker with network access to Windows DNS Server could execute arbitrary code on the system, potentially disrupting DNS resolution services or allowing further network compromise. This affects DNS infrastructure that supports operational technology network name resolution.
Who's at risk
Water utilities and municipal electric companies running Windows Server 2025 as DNS infrastructure supporting SCADA networks, RTUs, or engineering workstations. Critical for organizations where DNS server handles name resolution for industrial control systems or business network separation.
How it could be exploited
An attacker with valid Windows domain credentials could send a specially crafted network request to the DNS service on a vulnerable Windows Server 2025 system, triggering a use-after-free memory condition. The attacker could then execute code with the privileges of the DNS service account, which typically has domain-level permissions.
Prerequisites
- Valid Windows domain user credentials
- Network access to DNS service (port 53 UDP/TCP)
- Windows Server 2025 running DNS role
- Server must not have received 2026-Sep security update
remotely exploitablerequires valid credentialsaffects DNS infrastructurehigh impact if compromised
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict DNS service network access to authorized clients and services only using Windows Firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2025
HOTFIXApply Windows Server 2025 security update from September 2026 (Build 10.0.26100.33438 or later)
Long-term hardening
0/1HARDENINGEnsure DNS service account has minimal required privileges; verify it is not a domain admin
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ffee8c57-a078-467c-97d7-c715dcf327b9Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.