Impact
Concurrent execution using a shared resource with improper synchronization results in a race condition and a use‑after‑free in the Windows DNS Server. An attacker who can send crafted DNS requests to the server can hijack the service process and execute arbitrary code. The weakness is a classic concurrency flaw (CWE‑362) that corrupts memory and triggers a use‑after‑free (CWE‑416), giving attackers the ability to take control of the DNS server.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, Windows 11 version 26H1, and Windows Server editions 2012 R2, 2016, 2019, 2022, and 2025—including both full installations and Server Core installations—are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, implying no current evidence of exploitation. Based on the description, it is inferred that the attacker must have the capability to send DNS queries to the server, so the likely attack vector is a network‑based approach from an authenticated or otherwise authorized user.
OpenCVE Enrichment