DNS hardening changes in the August 2024 security update may cause timeout errors for outdated domain configurations
After installing the Windows August 2024 security update, DNS Server Security hardening changes to address CVE-2024-37968 may result in SERVFAIL or timeout errors for DNS query requests. These errors may occur if the domain configurations are out of date.
When will this happen:
The errors may occur after installing the Windows August 2024 security update, released August 13, 2024.
What you need to do to prepare:
To prepare for DNS hardening changes coming in the August 2024 security update, domain owners should ensure the DNS configurations for the domains are up-to-date and there is no stale data related to the domains.
Additional information:
The DNS Server Security hardening changes to address CVE-2024-37968 affect the following Windows versions:
- Windows Server, version 23H2
- Windows Server 2022
- Windows Server 2019
- Windows Server 2016
- Windows Server 2012 R2
- Windows Server 2012
- Windows Server 2008 R2 Service Pack 1
- Windows Server 2008 SP2
Message ID: MC860722