Impact
A numeric truncation error in the Windows DNS component allows an attacker who already has local access to elevate their privileges. The flaw permits a larger numeric value to be truncated to a smaller one during DNS processing, providing a bypass of security checks and the ability to run privileged code or modify system configuration. The vulnerability is categorized as CWE-122 and CWE-197 and can let a legitimate local user gain higher authority on the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012 (including Server Core), 2012 R2 (including Server Core), 2016, 2019, 2022, and 2025.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation has not yet been widely observed. Based on the description, it is inferred that the flaw requires local authorization; an attacker must already have some level of access to the target machine. No remote or network-based attack vector is documented, limiting the risk until a public exploit or automated tool becomes available.
OpenCVE Enrichment