9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
CVE-2026-41096 - Crash PoC Heap overflow in DnsRawTruncateMessageForUdp dnsapi.dll. A crafted DNS response with QDCOUNT=0 and a large OPT record causes a 604-byte heap overflow when the truncation logic miscalculates the destination pointer. MSRC...
Basic Information
ID
74CC6AFB-86FC-5129-80CC-141F1D29B338
Published
May 24, 2026 at 14:23
Modified
May 24, 2026 at 14:25