The practical concern is straightforward. An unauthenticated attacker could send a specially crafted packet to an affected service over the network; if exploitation succeeds, the attacker could execute code on the target system. No authentication or user interaction is required. DNS is infrastructure rather than desktop wallpaper—when it is exposed, a high-impact defect deserves prompt attention even when exploiting it is technically demanding.
CVE-2026-72987 at a glance
- CVE: CVE-2026-72987
- Exact title: Windows DNS Remote Code Execution Vulnerability
- Severity: Critical
- CVSS base score: 8.1
- CVSS temporal score: 7.1
- CVSS vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - CWE: CWE-416
- Publicly disclosed: No
- Exploited: No
- Customer action required: Yes
- Exploitation assessment: Exploitation Unlikely
Microsoft’s CVSS vector describes a network-reachable issue with no privileges or user interaction required, and high potential impact to confidentiality, integrity, and availability. The important counterweight is AC:H: attack complexity is high.
Microsoft explains that successful exploitation requires “a deep understanding of the system and the ability to manipulate its components to trigger a specific condition.” Exploitation is not guaranteed and can depend on the environment, system configuration, and additional security measures. In other words: this is not a casual drive-by bug, but the potential outcome is serious enough that it should not be allowed to linger in an unpatched DNS estate.
Affected products and fixed builds
The remediation is version-specific. Administrators should match the installed product to the appropriate KB and confirm that the system reaches the stated fixed build.
| Affected product | Required update | Vendor fixed version |
|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems (x86) | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1607 for x64-based Systems | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1809 for 32-bit Systems (x86) | KB5122876 | 10.0.17763.9245 |
| Windows 10 Version 1809 for x64-based Systems | KB5122876 | 10.0.17763.9245 |
| Windows Server 2012 (Server Core installation) (x64) | KB5123065 | 6.2.9200.26349 |
| Windows Server 2012 (x64) | KB5123065 | 6.2.9200.26349 |
| Windows Server 2012 R2 (Server Core installation) (x64) | KB5123066 | 6.3.9600.23398 |
| Windows Server 2012 R2 (x64) | KB5123066 | 6.3.9600.23398 |
| Windows Server 2016 (Server Core installation) (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2016 (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2019 (Server Core installation) (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2019 (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2022 (Server Core installation) (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2022 (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2025 (Server Core installation) (x64) | KB5122871 | 10.0.26100.33438 |
| Windows Server 2025 (x64) | KB5122871 | 10.0.26100.33438 |
Required remediation by platform
- For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
- For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
- For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
- For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
- For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
- For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
- For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
- For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
What administrators should prioritize
The supplied Microsoft remediation data yields a useful operational distinction: KB5123099 covers both Windows 10 Version 1607 and Windows Server 2016, while KB5122876 covers Windows 10 Version 1809 and Windows Server 2019. That shared KB mapping can help patch teams organize deployments by servicing family without confusing the target fixed build.
Prioritize systems that provide affected Windows DNS services and validate their post-update build against the table above. Include Server Core deployments in that review; the flaw’s affected-product list explicitly includes them. The absence of a graphical shell does not make a DNS role less consequential—packets are famously indifferent to user interfaces.
CVE-2026-72987 combines remote reachability, no required authentication, and potential code execution with a high-complexity exploitation requirement. Microsoft assesses exploitation as unlikely, but also marks customer action as required. For organizations operating affected Windows DNS infrastructure, the sensible course is clear: deploy the matching KB and verify the required fixed build.
References
- Official MSRC or vendor evidence api.msrc.microsoft.com
- Official MSRC or vendor evidence msrc.microsoft.com
- Official MSRC or vendor evidence api.msrc.microsoft.com