PT-2026-40237 · Microsoft · Windows Dns+1
Published
2026-05-12
·
Updated
2026-06-24
·
CVE-2026-41096
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows DNS Client (affected versions not specified)
Description
A heap-based buffer overflow exists in the Microsoft Windows DNS Client, specifically within the
dnsapi.dll component. This issue occurs during the processing of DNS responses and is linked to the DNSQueryRaw() API, which allows applications to send raw DNS queries and receive responses without standard normalization and filtering. An unauthorized remote attacker can exploit this by sending a malicious DNS response via a rogue DNS server, a poisoned resolver, a compromised router, hostile Wi-Fi, or a man-in-the-middle position. This is a zero-click exploit that does not require user interaction and can allow the attacker to execute arbitrary code with high privileges, potentially reaching SYSTEM level.Recommendations
Deploy the May 2026 cumulative updates.
Restrict DNS traffic to trusted resolvers where possible.
Monitor
Dnscache and svchost.exe for abnormal child processes or unexpected outbound activity.Exploit
Fix
DoS
LPE
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Dns