Description
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Published: 2026-08-11
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the Windows DNS Server that permits an unauthorized attacker to execute arbitrary code when the DNS server processes a malicious request. This flaw is classified as CWE‑416, a memory corruption weakness that allows an attacker to gain code execution privileges over the target system. The outcome is full compromise of the DNS server, which could then be used for further lateral movement or denial of service against network services.

Affected Systems

Microsoft Windows 10 releases 1607 and 1809, as well as Microsoft Windows Server 2016 (including Server Core), Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core). All of these operating systems include the vulnerable DNS Server component and are therefore affected.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity risk. EPSS score of 0.00454 (< 1%) indicates a very low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread public exploitation has not yet been observed. The likely attack vector is network‑based, as the flaw is triggered by a specially crafted DNS query sent to the vulnerable DNS server. An attacker with network access can trigger the use‑after‑free condition, leading to remote code execution without any authenticated access.

Generated by OpenCVE AI on August 12, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest security update for Windows DNS Server from the Microsoft Security Response Center. This update resolves the use‑after‑free condition in the DNS Server component.
  • If the update cannot be applied immediately, isolate the DNS server from untrusted or external networks to reduce the exposure to malicious DNS traffic. Ensure that the DNS server only receives requests from trusted infrastructure or VPN endpoints.
  • Enable DNS auditing and monitoring on the server to detect and alert on suspicious or malformed DNS queries that could indicate exploitation attempts.

Generated by OpenCVE AI on August 12, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Title Windows DNS Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows Server 2016 Windows Server 2016 (server Core Installation) Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:44.833Z

Reserved: 2026-07-22T21:30:09.120Z

Link: CVE-2026-65789

cve-icon Vulnrichment

Updated: 2026-08-12T13:41:36.380Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:58.730

Modified: 2026-08-17T19:04:05.863

Link: CVE-2026-65789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:15:03Z

Weaknesses