CVE-2026-77505 – Windows DNS Server Remote Code Execution Vulnerability

CVSS 8.1 IMPORTANT Critical - Same Day Deployment

“A malicious DNS query could turn a timing flaw into SYSTEM-level code execution on a vulnerable DNS server.”

CVE-2026-77505 is a critical use-after-free vulnerability in Windows DNS Server. An unauthenticated attacker with network access could send specially timed DNS queries to a DNS server configured with a server-level DNS plug-in and attempt to trigger a race condition. Successful exploitation could result in remote code execution with SYSTEM privileges. The vulnerability is not publicly disclosed and is not currently reported as exploited.

Key Details

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.