CVE-2021-26897: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26877, CVE-2021-26893, CVE-2021-26894, CVE-2021-26895.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.19968Patch KB5000853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21070Patch KB5000856 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23298Patch KB5000840 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.24566Patch KB5000851 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4283Patch KB5000803 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26897?
CVE-2021-26897 has a critical severity rating which indicates a high potential for exploitation.
How do I fix CVE-2021-26897?
To fix CVE-2021-26897, apply the latest security updates provided by Microsoft for the affected Windows Server versions.
Which versions of Windows are affected by CVE-2021-26897?
CVE-2021-26897 affects Windows Server 2008, 2012, 2016, and 2019.
What type of vulnerability is CVE-2021-26897?
CVE-2021-26897 is categorized as a Remote Code Execution vulnerability.
What are the potential impacts of CVE-2021-26897?
If exploited, CVE-2021-26897 could allow an attacker to execute arbitrary code on the affected Windows DNS Server.