CVE-2026-62817: Windows DNS Server Remote Code Execution Vulnerability
Overview
- Severity
- High (CVSS 8.8)
- CVSS Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Remote Code Execution
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
- Last Updated
- 2026-09-08
- EPSS Score
- 0.53% (percentile: 42.7%)
Description
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
FAQ
How could an attacker exploit this vulnerability?
Successful exploitation of this vulnerability could allow an attacker the ability to gain remote code execution via an in-network attacker calling arbitrary endpoints.
Affected Products (6)
Windows
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server 2025 (Server Core installation)
- Windows Server 2025
Security Updates (5)
Revision History
- 2026-08-11: Information published.
- 2026-09-08: Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only.