CVE-2026-62817 – Windows DNS Server Remote Code Execution Vulnerability
CVSS 8.8
IMPORTANT
2 Critical – Same Day Deployment
“An attacker already on the network could turn a malformed DNS request into remote code execution on a critical infrastructure server.”
CVE-2026-62817 is a remote code execution vulnerability in Windows DNS Server caused by an out-of-bounds write. An unauthenticated attacker on an adjacent network could exploit the flaw by interacting with arbitrary endpoints and potentially execute code on the target system. The attack has low complexity and requires no privileges or user interaction.
Key Details
- Affected Product
- Microsoft Windows 10 1809
- Attack Vector
- Adjacent
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-787
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.