Vulnerability record · CVE-2011-0657 · published 13 April 2011
CVE-2011-0657: Microsoft Windows DNS client remote code execution via crafted DNS/LLMNR query
Microsoft · Windows 2003 Server
The DNS client component (DNSAPI.dll) in multiple Windows versions fails to properly process DNS queries, allowing remote code execution through a crafted LLMNR broadcast query or a crafted application. This is a critical, network-reachable flaw affecting legacy Windows platforms that are still deployed in some environments.
Description
DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.1 score of 9.8 with network vector, no privileges or user interaction required, and high EPSS percentile indicate severe risk despite lack of KEV listing.
What it is
The DNS client component (DNSAPI.dll) in multiple Windows versions fails to properly process DNS queries, allowing remote code execution through a crafted LLMNR broadcast query or a crafted application. This is a critical, network-reachable flaw affecting legacy Windows platforms that are still deployed in some environments.
Impact
A remote attacker can execute arbitrary code with the privileges of the affected process, potentially leading to full system compromise. No user interaction or authentication is required for the LLMNR broadcast vector.
Attack surface
Reachable over the network via a crafted LLMNR broadcast query (AV:N, PR:N, UI:N) or locally via a crafted application. No authentication or user interaction is needed for the network vector.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS probability is 0.62495 (99.151 percentile), indicating a high likelihood of exploitation activity, though no public exploit references are tagged in the record.
What to do
- Apply Microsoft security bulletin MS11-030 (patch) to all affected Windows versions immediately.
- Disable LLMNR where not required via Group Policy to remove the broadcast attack vector.
- Segment or isolate legacy Windows XP, Server 2003, Vista, Server 2008, and Windows 7 systems that cannot be patched.
- Monitor for and restrict unnecessary inbound LLMNR traffic at network boundaries.
Detection
- Monitor network traffic for anomalous LLMNR broadcast queries, especially malformed or oversized packets.
- Audit endpoint logs for unexpected DNSAPI.dll crashes or process creation from DNS client processes.
- Use host-based detection to flag suspicious child processes spawned by svchost.exe or DNS client services.
- Check for missing MS11-030 patch status across affected Windows hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0657 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0657), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.