Windows DNS
by Microsoft
CVEs (31)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62878 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2026 | Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-41096 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2026 | Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62817 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-65789 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62820 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62778 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2021-36968 | Hig | 0.51 | 7.8 | 0.01 | Sep 15, 2021 | Windows DNS Elevation of Privilege Vulnerability | ||
| CVE-2026-62787 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2026 | Use after free in Windows DNS allows an authorized attacker to execute code over a network. | ||
| CVE-2024-37968 | Hig | 0.49 | 7.5 | 0.01 | Aug 13, 2024 | Windows DNS Spoofing Vulnerability | ||
| CVE-2023-35622 | Hig | 0.49 | 7.5 | 0.02 | Dec 12, 2023 | Windows DNS Spoofing Vulnerability | ||
| CVE-2020-1228 | Hig | 0.49 | 7.5 | 0.04 | Sep 11, 2020 | A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive. To exploit the vulnerability, an authenticated attacker… | ||
| CVE-2020-0836 | Hig | 0.49 | 7.5 | 0.05 | Sep 11, 2020 | A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive. To exploit the vulnerability, an authenticated attacker… | ||
| CVE-2026-41108 | Hig | 0.46 | 7.0 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70330 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70304 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65799 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65798 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65797 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65795 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62883 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.02
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
- risk 0.51cvss 7.8epss 0.01
Windows DNS Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.01
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Windows DNS Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows DNS Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.04
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive. To exploit the vulnerability, an authenticated attacker…
- risk 0.49cvss 7.5epss 0.05
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive. To exploit the vulnerability, an authenticated attacker…
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Page 1 of 2