Windows DNS Server Remote Code Execution Vulnerability
Plan PatchCVSS 8.1CVE-2026-77505Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows DNS Server allows an unauthenticated attacker to execute arbitrary code over the network by sending specially crafted DNS requests. Affected versions include Windows Server 2016, 2019, 2022, 2025, and Windows 10 versions 1607 and 1809. Microsoft has released security updates for all affected products. Exploitation is assessed as less likely at this time.
What this means
What could happen
An attacker could send specially crafted network requests to a Windows DNS Server to execute arbitrary code on that server, potentially allowing them to take control of the DNS service and redirect network traffic or disrupt name resolution for the entire facility.
Who's at risk
Windows Server administrators running DNS Server roles on Windows Server 2016, 2019, 2022, or 2025; and IT managers operating Windows 10 systems with DNS Server features enabled. This affects any organization using Windows-based DNS infrastructure.
How it could be exploited
An attacker sends malicious DNS queries or responses to a vulnerable Windows DNS Server over the network. The use-after-free vulnerability in the DNS Server processing code allows the attacker's malformed request to trigger code execution without authentication. This could give the attacker control over DNS resolution, affecting all systems that depend on that server for name lookups.
Prerequisites
- Network connectivity to port 53 (DNS) on the Windows DNS Server
- DNS Server role enabled and listening for DNS queries
- Windows Server 2016, 2019, 2022, or 2025; or Windows 10 versions 1607 or 1809
remotely exploitableno authentication requiredaffects critical network infrastructure (DNS)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to DNS Server port 53 using firewall rules to only allow queries from authorized internal subnets and clients
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Sep security update to all Windows DNS Servers
Long-term hardening
0/1HARDENINGMonitor DNS Server logs for unusual queries or connection attempts that may indicate exploitation attempts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b5f610ca-205f-45d4-bcb3-2b8846910027Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.