Impact
The vulnerability is a Use‑After‑Free flaw in the Windows DNS server that allows an attacker with network access to trigger a crash of the DNS service. When the service terminates as a result, network name resolution fails until the device is restarted, causing a denial of service for any application that relies on DNS within the affected system.
Affected Systems
Microsoft Windows 10 (Version 1607 and Version 1809) and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including core installations, are affected by the flaw.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity. No EPSS score is available and the vulnerability is not currently listed in the CISA KEV catalog, suggesting no widespread exploitation to date. The attack vector is likely network‑based, requiring an attacker to send specially crafted DNS queries to the vulnerable DNS service, which is accessible from the network, thereby enabling an unprivileged network attacker to force a service restart and disrupt DNS availability.
OpenCVE Enrichment