Impact
A use‑after‑free flaw in Microsoft Windows DNS Server allows an unauthorized attacker to cause code execution on the system. The vulnerability is formally identified as CWE‑416 and carries a CVSS score of 8.1, indicating a high‑severity risk. When exploited, the attacker can run arbitrary code with the privileges of the DNS Server service, potentially compromising the entire host and any services it supports.
Affected Systems
The flaw affects Microsoft Windows 10 Version 1607 and Version 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations). Only the versions listed in the CNA data are known to be vulnerable; no other builds are reported.
Risk and Exploitability
The CVSS score of 8.1 denotes a high severity, and the EPSS score is < 1 %, indicating a low but non‑zero likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Attackers can target the vulnerability remotely over the network by sending malicious DNS traffic to a vulnerable DNS Server, exploiting the use‑after‑free condition to gain code execution. No special user privileges or configuration are required beyond network reachability.
OpenCVE Enrichment