CVE-2026-62817: Windows DNS Server Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11
Last Updated
2026-09-08
EPSS Score
0.53% (percentile: 42.7%)

Description

Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.

FAQ

How could an attacker exploit this vulnerability? Successful exploitation of this vulnerability could allow an attacker the ability to gain remote code execution via an in-network attacker calling arbitrary endpoints.

Affected Products (6)

Windows

  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2025 (Server Core installation)
  • Windows Server 2025

Security Updates (5)

Revision History

  • 2026-08-11: Information published.
  • 2026-09-08: Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only.