logo

Seven Windows Wonders – Critical Vulnerabilities in DNS Dynamic Updates

ID: 007e0e86-e697-577d-bc65-374e7d65c3c4

STIX ID: report--007e0e86-e697-577d-bc65-374e7d65c3c4

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2021-03-09

Date Updated: 2026-04-28

Author: Eoin Carroll

...
...

Microsoft disclosed seven critical DNS Dynamic Update vulnerabilities in March 2021 (five RCEs with CVSS 9.8 and two DoS). This report analyzes CVE-2021-26877 and CVE-2021-26897 in depth, describing heap out-of-bounds read/write conditions that can lead to RCE on Primary Authoritative DNS servers, outlines exploitation prerequisites (Dynamic Update write access or a compromised domain-joined machine), states the issues are not wormable and not observed in the wild, and urges urgent patching and/or deployment of network signatures as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.