Impact
An out‑of‑bounds write in the Windows DNS server allows an attacker with network access to submit crafted DNS responses that overwrite adjacent memory and ultimately execute arbitrary code. Once exploited, the attacker can gain the privileges under which the DNS server process runs, potentially leading to full system compromise.
Affected Systems
Affected are Microsoft Windows 10 versions 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2019 (including Server Core), 2022 and 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity flaw. The EPSS score is not available, so the current likelihood of exploitation is uncertain; however, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the DNS protocol, where an unauthorized entity on an adjacent network can send malicious DNS packets to the vulnerable server. Successful exploitation would provide remote code execution capability on the affected system.
OpenCVE Enrichment