CVE-2025-24064

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 416

Summary

CVE-2025-24064 is a recently disclosed vulnerability affecting DNS servers. This issue permits unauthorized attackers to execute code remotely due to a use-after-free condition. The vulnerability arises when the server fails to properly manage memory after freeing it. An attacker can exploit this flaw by crafting malicious DNS queries, leading to arbitrary code execution over a network. This vulnerability poses a significant risk and requires immediate attention from DNS server administrators to apply available patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share