Our server (windows 2008 R2 server, fully patched) this morning was a bit slow.
Checking network activity I found several DNS sessions using quite a lot of bandwidth (10MB/sec per session). This was rather suspicious (I expect DNS traffic to be light) so I turned off DNS for the present.
Here is an image of some of the connections:
As you can see there is a varied list of hosts. Is this a vulnerability in DNS?