Impact
Improper access control in Microsoft Windows DNS (CWE‑284) allows an authorized local attacker to alter the DNS client configuration, potentially redirecting network traffic to malicious servers and compromising the confidentiality and integrity of all applications on the affected machine.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2019, including both standard and Server Core editions; Microsoft Windows Server 2022; and Microsoft Windows Server 2025, including both standard and Server Core editions are affected.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity vulnerability, while the EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local privileged user or legitimate administrator who can modify DNS client settings, and exploitation would involve changing DNS configuration to redirect traffic. Conditions are limited to users who can access the configuration files or system settings.
OpenCVE Enrichment