Impact
The vulnerability is a use‑after‑free flaw in the Windows DNS server that permits an unauthorized network attacker to execute code on the target system. The flaw can be triggered remotely by sending carefully crafted DNS requests, leading to arbitrary code execution without authentication. The impact is full compromise of the affected machine, allowing attackers to gain control of the system, exfiltrate data, or deploy malware.
Affected Systems
Microsoft Windows 10 (features 1607 and 1809) and a range of Windows Server editions from Server 2012 through Server 2025, including core and full installations.
Risk and Exploitability
The CVSS score of 8.1 signals a high severity risk. While the EPSS score is not available, the vulnerability’s remote, unauthenticated nature and lack of a KEV listing suggest that exploitation is plausible but not yet proven in the wild. Attackers would likely send malicious DNS traffic to the vulnerable service; success would grant arbitrary code execution with the privileges of the DNS service, which often allows privilege escalation to system level.
OpenCVE Enrichment