Impact
The vulnerability is a use‑after‑free flaw in the Windows DNS client that lets an attacker send malicious DNS traffic to a vulnerable computer, causing the system to execute code with elevated privileges. This flaw can be leveraged to gain local administrator rights, giving an attacker unrestricted access to sensitive data, configuration information, and the ability to install or modify software on the affected machine.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2 and 26H1, and Windows Server 2025 installations including Server Core are susceptible to this flaw.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1 % suggests the exploitation likelihood is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be remote over a network, requiring the attacker to be able to send specially crafted DNS queries to the vulnerable client. Successful exploitation would raise the attacker’s privileges to local administrator on the targeted system.
OpenCVE Enrichment