Impact
The vulnerability is a use‑after‑free flaw in the Windows DNS Server that can be triggered by a maliciously crafted DNS request. When the server improperly accesses freed memory, an attacker may cause the server to execute arbitrary code, which could allow full compromise of the affected system.
Affected Systems
Microsoft Windows Server 2025, including the Server Core variant, is affected as listed by the CNA. No more granular version information is provided.
Risk and Exploitability
The CVSS score of 8 indicates high severity. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The likely attack vector is network‑based interaction with the DNS service by an authorized attacker; the description refers to an \"authorized attacker\", so it is inferred that some level of network privilege or authentication is required. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment