CVE-2021-26896: Windows DNS Server Denial of Service Vulnerability
Windows DNS Server Denial of Service Vulnerability This CVE ID is unique from CVE-2021-27063.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23298Patch KB5000840 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.24566Patch KB5000851 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.19968Patch KB5000853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21070Patch KB5000856 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4283Patch KB5000803 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808
Event History
Frequently Asked Questions
Which systems should be prioritized for review?
Review Microsoft Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, and 2019 systems that provide DNS server functionality.
What access does an attacker need to exploit this issue?
The CVSS vector indicates network-based exploitation with low attack complexity. It requires no privileges and no user interaction.
What is the expected security impact?
The reported impact is limited to availability; confidentiality and integrity impacts are listed as none. Successful exploitation can cause a denial of service.