PT-2026-40237 · Microsoft · Windows Dns+1

CVE-2026-41096

·

Published

2026-05-12

·

Updated

2026-09-12

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows DNS Client (affected versions not specified)
Description A heap-based buffer overflow exists in the Microsoft Windows DNS Client, specifically within the dnsapi.dll component. This issue occurs during the processing of DNS responses and can be triggered via the DNSQueryRaw() API, which allows applications to send raw DNS queries and receive responses without standard normalization and filtering. An unauthorized remote attacker can exploit this by sending a specially crafted malicious DNS response. This can be achieved through a rogue DNS server, a poisoned resolver, a compromised router, hostile Wi-Fi, or a man-in-the-middle position. Successful exploitation allows for zero-click remote code execution with high privileges, potentially reaching the SYSTEM level, granting the attacker total control over the affected machine.
Recommendations Deploy the May 2026 cumulative updates. Restrict DNS traffic to trusted resolvers where possible. Monitor Dnscache and svchost.exe for abnormal child processes or unexpected outbound activity.

Exploit

Fix

LPE

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06863
CVE-2026-41096

Affected Products

Windows
Windows Dns