Back

CVE-2018-8626

CRITICAL

A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.

Published: Dec 12, 2018 Modified: Jun 17, 2026
CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (9)

Vendor Product Version
microsoft windows_10 1607
microsoft windows_10 1709
microsoft windows_10 1803
microsoft windows_10 1809
microsoft windows_server_2012 r2
microsoft windows_server_2016 -
microsoft windows_server_2016 1709
microsoft windows_server_2016 1803
microsoft windows_server_2019 -

GitHub Security Advisory GHSA-r9mj-8p57-hmj9

A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 21.12%

Top 3% most likely to be exploited

Threat Score 45.5 / 100

Data Sources

NVD EPSS GitHub