Impact
This vulnerability is an integer overflow or wraparound in the Windows DNS service. An unauthenticated attacker can send a specially crafted DNS request that causes the service to consume resources or crash, effectively denying legitimate DNS traffic. The flaw is related to improper integer handling of packet lengths and is classified as CWE-190. The impact is loss of availability of DNS services for authorized users and potential network disruption.
Affected Systems
All Microsoft Windows 10 releases version 1607 and 1809 and all Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations) are affected. The supplied data does not specify sub‑version or build identifiers beyond these major releases.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity. EPSS score of 1% indicates a very low but non-zero exploitation probability, though the vulnerability remains network accessible as it involves the DNS service listening on port 53. Since the attacker need not be authenticated, the attack vector is remote and based on network traffic. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploited instances at the time of this report.
OpenCVE Enrichment