Impact
The flaw is an improper privilege management issue in Microsoft Windows DNS that lets an attacker with local authorized access bypass the Zero Trust DNS security feature. This is a local security feature bypass and is categorized as CWE‑269, indicating incorrect handling of privilege levels. Based on the description, it is inferred that bypassing the Zero Trust DNS controls could allow faster exploitation of additional trusted services or elevation to higher access on the system.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025, including the Server Core edition, are affected by this vulnerability as identified in the CNA advisory.
Risk and Exploitability
Based on the description, the likely attack vector is local: a user who already has authorized access to the machine can leverage the flaw to bypass DNS security controls, potentially enabling further privileged operations. The CVSS score of 5.5 rates the vulnerability as moderate in severity and the EPSS score of less than 1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment