Impact
The vulnerability is a stack‑based buffer overflow in the Windows DNS server. An attacker who can send crafted DNS requests to the vulnerable server can trigger the overflow and execute arbitrary code. Because the DNS server typically runs with elevated privileges, this can lead to full system compromise of the affected host and potentially enable lateral movement into the network. The flaw is identified as CWE‑121 and carries a CVSS score of 9.8, indicating a very severe risk.
Affected Systems
Microsoft Windows 10 (Version 1607 and 1809) and Windows Server 2012 through Windows Server 2025, including all standard and Server Core installations, are affected by this vulnerability.
Risk and Exploitability
The flaw can be triggered by an unauthenticated network attacker through crafted DNS packets; no user interaction is required. The high CVSS score, the absence of any EPSS score, and the lack of inclusion in the CISA KEV catalog mean that exposed DNS servers remain at very high risk until patched. An attacker exploiting this vulnerability could gain complete control of the compromised host and use it as a foothold to compromise other systems on the network.
OpenCVE Enrichment