Description
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper privilege management issue in Microsoft Windows DNS that lets an attacker with local authorized access bypass the Zero Trust DNS security feature. This is a local security feature bypass and is categorized as CWE‑269, indicating incorrect handling of privilege levels. Based on the description, it is inferred that bypassing the Zero Trust DNS controls could allow faster exploitation of additional trusted services or elevation to higher access on the system.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025, including the Server Core edition, are affected by this vulnerability as identified in the CNA advisory.

Risk and Exploitability

Based on the description, the likely attack vector is local: a user who already has authorized access to the machine can leverage the flaw to bypass DNS security controls, potentially enabling further privileged operations. The CVSS score of 5.5 rates the vulnerability as moderate in severity and the EPSS score of less than 1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 1, 2026 at 09:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft update that fixes DNS security feature privilege handling for Windows 11 24H2, 25H2, 26H1, and Windows Server 2025.
  • Ensure that the Zero Trust DNS Security Feature remains enabled and correctly configured after the patch is installed.
  • Monitor DNS requests and system logs for any unauthorized attempts to modify DNS settings or suspicious local access patterns.

Generated by OpenCVE AI on August 1, 2026 at 09:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
Title Windows Zero Trust DNS Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-269
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:23:51.415Z

Reserved: 2026-06-04T17:30:16.974Z

Link: CVE-2026-50295

cve-icon Vulnrichment

Updated: 2026-07-14T19:21:59.149Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:00:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management