Description
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
Published: 2026-07-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a relative path traversal flaw in the Windows DNS Server that permits an attacker with authorized access to execute arbitrary code on a target system over an adjacent network. The flaw allows manipulation of file paths to bypass normal file access restrictions, enabling code execution on the target machine.

Affected Systems

The vulnerability affects Microsoft Windows operating systems, including Windows 10 versions 1607 and 1809 and all Windows Server releases from 2012 through 2025. Both full and Server Core installations are impacted. These systems run DNS Server services that, when left unpatched, can be abused by attackers who have legitimate credentials within the same network or have local administrative rights.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity level. The EPSS score of less than 1% shows a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an authorized attacker, such as an insider or compromised account, to perform the exploit remotely within the same LAN or adjacent network segment. Consequently, while the technical capabilities are significant, the practical risk remains contingent on internal security posture and user privileges.

Generated by OpenCVE AI on July 31, 2026 at 07:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE-2026-50426 as soon as possible.
  • Configure DNS Server to enforce strict path validation and deny write permissions for directory traversal attempts.
  • Segment the network to isolate DNS servers from untrusted hosts and implement least‑privilege controls for all administrative access.

Generated by OpenCVE AI on July 31, 2026 at 07:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
Title Windows DNS Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-23
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:55:35.604Z

Reserved: 2026-06-04T18:57:47.375Z

Link: CVE-2026-50426

cve-icon Vulnrichment

Updated: 2026-07-29T18:24:04.717Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:00:04Z

Weaknesses
  • CWE-23

    Relative Path Traversal