Description
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Use after free in the Windows DNS server allows an authorized attacker to execute arbitrary code within the DNS service’s context. The flaw occurs when the server accesses memory that has already been freed; a carefully crafted DNS request can manipulate the execution path and trigger code execution. An attacker who can send such requests from a trusted network location—such as a compromised workstation or a privileged user—can gain control of the DNS server process.

Affected Systems

The vulnerability affects Microsoft Windows 10 (Version 1607 and 1809) and a broad set of Windows Server releases from 2012 through 2025, including Server Core installations. All affected instances run the DNS Server service on the listed operating systems.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity risk. Although the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the potential for exploitation remains significant in environments where the DNS server is exposed to trusted internal networks. An attacker with network-level access can craft malicious DNS packets to trigger the use‑after‑free, leading to remote code execution with the privileges of the DNS service, which commonly operates under elevated system accounts.

Generated by OpenCVE AI on September 10, 2026 at 01:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update or cumulative patch that addresses CVE-2026-69551, as documented on the Microsoft update guide.
  • Restrict inbound DNS traffic to trusted IP ranges or VLANs by configuring firewall rules or DNS access‑control lists to reduce the exposed attack surface.
  • Run the DNS Server service under the least‑privilege account available, and consider isolating the service on a dedicated, hardened host or within a container to limit the impact of potential compromise.

Generated by OpenCVE AI on September 10, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows DNS allows an authorized attacker to execute code over a network.
Title Windows DNS Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows Server 2012 Windows Server 2012 (server Core Installation) Windows Server 2012 R2 Windows Server 2012 R2 Windows Server 2012 R2 (server Core Installation) Windows Server 2016 Windows Server 2016 (server Core Installation) Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:31:33.608Z

Reserved: 2026-08-03T21:15:56.834Z

Link: CVE-2026-69551

cve-icon Vulnrichment

Updated: 2026-09-09T19:07:30.536Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:23.677

Modified: 2026-09-24T23:18:05.170

Link: CVE-2026-69551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:11:32Z

Weaknesses