Impact
Windows DNS Server is vulnerable to a use‑after‑free condition that allows an authorized attacker to execute code over the network. The flaw can lead to arbitrary code execution, potentially compromising system integrity and confidentiality. This weakness is classified as CWE-416, indicating improper handling of freed memory leading to a vulnerability that an attacker can exploit.
Affected Systems
Microsoft Windows Server 2025 and its Server Core installation are affected. No specific sub‑version information is provided, so all current or future releases of Windows Server 2025 should be considered at risk until Microsoft releases a patch.
Risk and Exploitability
The CVSS score of 7.5 marks this as a high‑severity vulnerability. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, but because it enables remote code execution in a critical network service, the risk remains significant. An attacker who can send crafted queries to the DNS server can trigger the unauthorized execution, assuming the attacker has sufficient privileges to interact with the DNS service.
OpenCVE Enrichment