Impact
A use‑after‑free condition in the Windows DNS Server enables an unauthorized attacker to run arbitrary code by sending specially crafted network traffic. The flaw allows remote execution without authentication, potentially compromising the integrity and confidentiality of the affected system.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607 and 1809, and all supported Windows Server releases from 2012 through 2025, including Server Core installations. Administrators should verify that their environment includes any of these operating systems.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity level. EPSS information is not available, so the probability of exploitation at this time is unknown, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is over the network; based on the description, it is inferred that an attacker can deliver the exploit without first authenticating to the DNS server.
OpenCVE Enrichment