Impact
This vulnerability is a use‑after‑free flaw in the Windows DNS Server that permits an unauthorized network attacker to execute arbitrary code. The weakness is identified as CWE‑416 and leads directly to remote code execution, which can compromise confidentiality, integrity, and availability of the affected host.
Affected Systems
The flaw affects Microsoft Windows Server 2022 and Windows Server 2025, including Server Core installations. No specific patch versions are listed.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity for remote exploitation. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via the DNS protocol over a network connection, and an attacker does not need elevated privileges on the system to exploit this flaw.
OpenCVE Enrichment