Windows DNS Server Stack Buffer Overflow Remote Code Execution
Stack-based buffer overflow in Windows DNS Server enables unauthenticated remote code execution. Affects Windows Server 2012 through 2025.
- Vendor
- Microsoft
- Product
- Windows DNS Server (Server 2012–2025)
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-62878 is a stack-based buffer overflow in the Windows DNS Server service, enabling remote code execution without authentication. The vulnerability spans a wide range of Windows Server versions — 2012 through 2025 — putting a large installed base at risk. DNS servers are frequently network-accessible, and in many environments internet-facing, making this a high-exposure target.
CVSS 9.8 (Critical). Not yet observed in active exploitation as of the August 2026 Patch Tuesday release, but the combination of wide version coverage, network reachability, and no authentication requirement makes it an attractive target for threat actors.
Affected products: Windows DNS Server on Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025.
Mitigation: Apply the August 2026 Patch Tuesday cumulative update. If patching is delayed, restrict DNS server access to trusted networks at the firewall layer; do not expose Windows DNS Server directly to the internet.
Priority: High — CVSS 9.8, wide version coverage, DNS servers are commonly network-reachable.
