Impact
A use‑after‑free flaw (CWE‑416) in the Windows DNS server allows an attacker to execute arbitrary code on the target system without authentication. This vulnerability enables unauthorized code execution, permitting full compromise of the DNS server and the potential to expand the attack across the network, thereby breaching confidentiality, integrity, and availability of network services.
Affected Systems
The flaw affects Microsoft Windows 10 Version 1607 and Windows 10 Version 1809, as well as Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, in both standard and Server Core configurations.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. No EPSS score is publicly available, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker would exploit the vulnerability by sending specially crafted DNS traffic over the network to trigger the use‑after‑free condition and gain code execution.
OpenCVE Enrichment