Impact
A numeric truncation error in the Windows DNS service allows an authorized local user to elevate privileges to a higher level. The flaw is a classic buffer overflow and calculation error (CWE-122 and CWE-197). An attacker who can trigger the vulnerable code path—typically by performing DNS operations with sufficient privileges—can gain administrative rights on the affected machine, compromising all confidentiality, integrity, and availability functions.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 – including both full and Server Core installations. These releases are explicitly cited as vulnerable.
Risk and Exploitability
The CVSS score of 6.7 indicates medium severity, but the exploit probability is unclear due to a missing EPSS rating. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits in the wild. Because the flaw requires local execution of DNS functions, the attack vector is local user privilege escalation. The risk is moderate: a successful exploitation would allow an attacker to acquire administrative rights on the impacted system.
OpenCVE Enrichment