Impact
Windows DNS Server contains a race condition caused by concurrent execution on a shared resource without proper synchronization. An unauthorized actor can exploit this flaw over the network to run arbitrary code with the privileges of the DNS service, leading to full control over the host system. The weakness is a race condition (CWE-362).
Affected Systems
The vulnerability affects Microsoft Windows 10 starting with version 1607 and 1809, as well as all Windows Server releases 2016, 2019, 2022, and 2025—including both full and Server Core installations.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score is not available, so the current exploitation probability is unknown, but the flaw can be triggered remotely without authentication, making it potentially exploitable in a wide range of network scenarios. The vulnerability is not listed in CISA KEV. Attackers can craft malicious DNS queries from anywhere on the network to activate the race condition, so the attack vector is essentially remote network traffic.
OpenCVE Enrichment