Microsoft Windows DNS
CVE-2018-8304 — Windows DNSAPI Denial of Service Vulnerability
Executive Summary
A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses. An attacker who successfully exploited the vulnerability could cause a system to stop responding. Note that the denial of service condition would not allow an attacker to execute code or to elevate user privileges. However, the denial of service condition could prevent authorized users from using system resources. To exploit the vulnerability, the attacker would use a malicious DNS server to send corrupted DNS responses to the target. The update addresses the vulnerability by modifying how Windows DNSAPI.dll handles DNS responses.
Overview
5.9
CVSS MEDIUM
Important
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
CVSS Vector
ATTACK VECTOR
Network
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
None
INTEGRITY
None
AVAILABILITY
High
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 5.3
EPSS Score
0.11796
probability of exploitation in the next 30 days
0.95709 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
6 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems 4338829 (Security Update) 4345455 (Alternate Cumulative) Important Denial of Service 4284860 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 10 for x64-based Systems 4338829 (Security Update) 4345455 (Alternate Cumulative) Important Denial of Service 4284860 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 10 Version 1607 for 32-bit Systems 4338814 (Security Update) 4345418 (Alternate Cumulative) Important Denial of Service 4284880 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 10 Version 1607 for x64-based Systems 4338814 (Security Update) 4345418 (Alternate Cumulative) Important Denial of Service 4284880 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 10 Version 1703 for 32-bit Systems 4338826 (Security Update) 4345419 (Alternate Cumulative) Important Denial of Service 4284874 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 10 Version 1703 for x64-based Systems 4338826 (Security Update) 4345419 (Alternate Cumulative) Important Denial of Service 4284874 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 10 Version 1709 for 32-bit Systems 4338825 (Security Update) 4345420 (Alternate Cumulative) Important Denial of Service 4284819 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 10 Version 1709 for x64-based Systems 4338825 (Security Update) 4345420 (Alternate Cumulative) Important Denial of Service 4284819 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 7 for 32-bit Systems Service Pack 1 4338818 (Monthly Rollup) 4338823 (Security Only) 4338821 (Preview Rollup) 4345459 (Standalone) Important Denial of Service 4284826 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 7 for x64-based Systems Service Pack 1 4338818 (Monthly Rollup) 4338823 (Security Only) 4338821 (Preview Rollup) 4345459 (Standalone) Important Denial of Service 4284826 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 8.1 for 32-bit systems 4338815 (Monthly Rollup) 4338824 (Security Only) 4338831 (Preview Rollup) 4345424 (Standalone) Important Denial of Service 4284815 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows 8.1 for x64-based systems 4338815 (Monthly Rollup) 4338824 (Security Only) 4338831 (Preview Rollup) 4345424 (Standalone) Important Denial of Service 4284815 Base: 5.9 Temporal: 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Yes None Windows RT 8.1 | 4338815 (Monthly Rollup) |
Important | Denial of Service | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | 4291391 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | 4291391 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2008 for Itanium-Based Systems Service Pack 2 | 4291391 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2008 for x64-based Systems Service Pack 2 | 4291391 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | 4291391 (Security Update) |
Important | Denial of Service | Yes |
Patches
2 patches
| Article | Type | Restart |
|---|---|---|
4338815 |
Monthly Rollup | Yes |
4291391 |
Security Update | Yes |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
Roberto Rodriguez ( @Cyb3rWard0g
Nick Freeman
References
On This Page