Three critical Windows DNS client vulnerabilities were patched today by Microsoft. The bugs could be abused by a man-in-the-middle attacker to run arbitrary code. Windows admins are advised to patch immediately; the bug affects Windows 8 and Windows 10 clients, and Windows Server 2012 and 2016. The bug traces back to the introduction of DNSSEC in the Microsoft operating system starting with Windows 8. An attacker on the local network could insert a malicious payload into a DNS response to a Windows machine’s DNS request and trigger the vulnerability.
Source: https://threatpost.com/microsoft-patches-critical-windows-dns-client-vulnerabilities/128344/