SB2024040960 - Multiple use-after-free vulnerabilities in Microsoft DNS Server



SB2024040960 - Multiple use-after-free vulnerabilities in Microsoft DNS Server

Published: April 9, 2024

Security Bulletin ID SB2024040960
Severity
Medium
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 secuirty vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2024-26223)

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when handling DNS queries. A remote user can send specially crafted DNS requests to the affected server and execute arbitrary code on the system, if the timing of DNS queries is perfect.


2) Use-after-free (CVE-ID: CVE-2024-26233)

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when handling DNS queries. A remote user can send specially crafted DNS requests to the affected server and execute arbitrary code on the system, if the timing of DNS queries is perfect.


3) Use-after-free (CVE-ID: CVE-2024-26231)

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when handling DNS queries. A remote user can send specially crafted DNS requests to the affected server and execute arbitrary code on the system, if the timing of DNS queries is perfect.


4) Use-after-free (CVE-ID: CVE-2024-26221)

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when handling DNS queries. A remote user can send specially crafted DNS requests to the affected server and execute arbitrary code on the system, if the timing of DNS queries is perfect.


5) Use-after-free (CVE-ID: CVE-2024-26222)

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when handling DNS queries. A remote user can send specially crafted DNS requests to the affected server and execute arbitrary code on the system, if the timing of DNS queries is perfect.


6) Use-after-free (CVE-ID: CVE-2024-26224)

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when handling DNS queries. A remote user can send specially crafted DNS requests to the affected server and execute arbitrary code on the system, if the timing of DNS queries is perfect.


7) Use-after-free (CVE-ID: CVE-2024-26227)

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when handling DNS queries. A remote user can send specially crafted DNS requests to the affected server and execute arbitrary code on the system, if the timing of DNS queries is perfect.



Remediation

Install update from vendor's website.