Windows DNS
by Microsoft
CVEs (31)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62881 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62769 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61920 | Med | 0.43 | 6.6 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network. | ||
| CVE-2020-0993 | Med | 0.43 | 6.5 | 0.05 | Apr 15, 2020 | A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'. | ||
| CVE-2021-28328 | Med | 0.42 | 6.5 | 0.02 | Apr 13, 2021 | Windows DNS Information Disclosure Vulnerability | ||
| CVE-2024-21377 | Med | 0.36 | 5.5 | 0.01 | Feb 13, 2024 | Windows DNS Information Disclosure Vulnerability | ||
| CVE-2023-32020 | Med | 0.36 | 5.6 | 0.01 | Jun 14, 2023 | Windows DNS Spoofing Vulnerability | ||
| CVE-2021-1637 | Med | 0.36 | 5.5 | 0.01 | Jan 12, 2021 | Windows DNS Query Information Disclosure Vulnerability | ||
| CVE-2026-50495 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-49174 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||
| CVE-1999-0275 | 0.00 | — | 0.06 | Jun 10, 1997 | Denial of service in Windows NT DNS servers by flooding port 53 with too many characters. |
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.43cvss 6.6epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.
- risk 0.43cvss 6.5epss 0.05
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'.
- risk 0.42cvss 6.5epss 0.02
Windows DNS Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows DNS Information Disclosure Vulnerability
- risk 0.36cvss 5.6epss 0.01
Windows DNS Spoofing Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows DNS Query Information Disclosure Vulnerability
- risk 0.00cvss 6.1epss 0.00
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
- risk 0.00cvss 6.1epss 0.00
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
- CVE-1999-0275Jun 10, 1997risk 0.00cvss —epss 0.06
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
Page 2 of 2