Impact
The vulnerability arises from a missing authentication check for a critical function in Microsoft Windows DNS, allowing an authorized local user to modify DNS client settings without permission. This can result in altered resolver behavior, potentially redirecting traffic to malicious hosts or exposing spoofed DNS responses. The weakness is a missing authentication boundary, classified as CWE‑306.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; Windows Server 2019, Server 2022, and Server 2025, including their Server Core installations. The affected builds include x86, x64, and arm64 architectures.
Risk and Exploitability
The CVSS score of 6.1 indicates medium severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw locally by possessing legitimate administrative or privileged user credentials; no remote access or network-level exploitation is required.
OpenCVE Enrichment