CVE-2025-24064: Windows Domain Name Service Remote Code Execution Vulnerability
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
Other sources
Windows Domain Name Service Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-24064?
CVE-2025-24064 is classified as a critical vulnerability due to its potential to allow remote code execution by unauthorized attackers.
How do I fix CVE-2025-24064?
To fix CVE-2025-24064, apply the latest security updates provided by Microsoft for affected Windows Server versions.
Which versions of Windows Server are affected by CVE-2025-24064?
CVE-2025-24064 affects multiple versions of Windows Server, including 2019, 2016, 2012, and 2008.
What are the potential impacts of CVE-2025-24064?
Exploiting CVE-2025-24064 can lead to complete system compromise, giving attackers the ability to execute arbitrary code.
Is there a workaround for CVE-2025-24064?
Currently, the only effective solution for CVE-2025-24064 is to install the security patches from Microsoft.