CVE-2026-62878 – Windows DNS Server Remote Code Execution Vulnerability
CVSS 9.8
CRITICAL
2 Critical – Same Day Deployment
“A single malicious network packet could turn an exposed Windows DNS service into a remote code execution target without credentials or user interaction.”
CVE-2026-62878 is a remote code execution vulnerability in Windows DNS Server caused by a stack-based buffer overflow. An unauthenticated attacker could send a specially crafted packet to an affected DNS service over the network and potentially execute code on the target system. The attack has low complexity, requires no privileges, and requires no user interaction.
Key Details
- Affected Product
- Microsoft Windows 10 1607
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-121
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.