CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-40776: Birthday Attack against Resolvers supporting ECS

highCVSS 8.6CVE-2025-40776

CSIRTS triage

What
A birthday attack against DNS resolvers supporting EDNS Client Subnet (ECS) extension allows cache poisoning or service disruption.
Who is affected
Authoritative and recursive DNS resolvers with ECS support enabled globally.
Urgency
High severity (CVSS 8.6) due to significant attack potential against critical DNS infrastructure.
Action
Disable ECS if not required, or update resolver to patched version implementing birthday attack mitigations.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch DNS Resolvers

Get an email when a new DNS Resolvers advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
high — CVSS 8.6
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-40776

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-40776coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center