Impact
The vulnerability is a use‑after‑free flaw in the Windows DNS Server that permits an unauthorized attacker to execute arbitrary code when the DNS server processes a malicious request. This flaw is classified as CWE‑416, a memory corruption weakness that allows an attacker to gain code execution privileges over the target system. The outcome is full compromise of the DNS server, which could then be used for further lateral movement or denial of service against network services.
Affected Systems
Microsoft Windows 10 releases 1607 and 1809, as well as Microsoft Windows Server 2016 (including Server Core), Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core). All of these operating systems include the vulnerable DNS Server component and are therefore affected.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity risk. EPSS score of 0.00454 (< 1%) indicates a very low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread public exploitation has not yet been observed. The likely attack vector is network‑based, as the flaw is triggered by a specially crafted DNS query sent to the vulnerable DNS server. An attacker with network access can trigger the use‑after‑free condition, leading to remote code execution without any authenticated access.
OpenCVE Enrichment