CVE-2026-62817
Windows DNS Server Remote Code Execution Vulnerability
Description
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
In plain language
AI Act nowThis is a serious flaw in Windows DNS Server that could let an attacker remotely run code if they can reach your DNS service; most small businesses should act quickly to patch if you run Windows DNS.
CVE-2026-62817 is a Windows DNS Server remote code execution vulnerability caused by an out-of-bounds write (CWE-787), where a remote attacker can trigger memory corruption over an adjacent network connection.
What to do now
- Check whether any device in your business runs the Windows DNS Server role (it can be a domain controller or a dedicated DNS server).
- Verify your Windows version/build and current patch level against the fixed versions listed below.
- Upgrade/patch Windows to the fixed version for your exact OS (listed in the next section) and reboot if required.
- If you cannot patch immediately, restrict network access to the DNS server (limit who can reach it) and monitor for unusual DNS-related traffic and crashes.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62817 and every CVE in our database. Create a free account — no credit card required.
Create Free Account