CVE-2025-24064
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Mar 11, 2025
CWE ID 416
Summary
CVE-2025-24064 is a recently disclosed vulnerability affecting DNS servers. This issue permits unauthorized attackers to execute code remotely due to a use-after-free condition. The vulnerability arises when the server fails to properly manage memory after freeing it. An attacker can exploit this flaw by crafting malicious DNS queries, leading to arbitrary code execution over a network. This vulnerability poses a significant risk and requires immediate attention from DNS server administrators to apply available patches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.