Impact
Windows DNS implements a request handling routine that contains a race condition leading to a use‑after‑free bug. An attacker who can send specially crafted DNS queries across the network can trigger the freeing of a memory object that is later accessed. This flaw allows the attacker to gain elevated privileges on the host machine, potentially achieving system‑level control. The weakness is categorized as CWE‑362 and CWE‑416.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, all major Windows Server releases from Server 2012 to Server 2025, including core installations, are impacted. The issue originates in the Windows DNS service bundled with these operating systems.
Risk and Exploitability
With a CVSS base score of 8.1 the vulnerability is considered high severity. EPSS data is not available, but the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The flaw can be exercised remotely over the network by an unauthorized attacker sending malicious DNS requests. Until a patch is applied the risk remains significant, as an attacker could acquire higher privileges and compromise the affected host.
OpenCVE Enrichment