Impact
The vulnerability is a numeric truncation error in the Windows DNS service that an attacker can exploit when they have local access. By causing the truncation, the attacker can alter data used by DNS and gain higher privileges than originally allowed, enabling elevated execution on the compromised machine. The weakness is identified as heap‑based buffer overflow (CWE‑122) and numeric truncation (CWE‑197). No remote code execution or denial of service is described, but the impact is a local privilege escalation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations, are affected by this CVE.
Risk and Exploitability
The CVSS score of 6.7 places this vulnerability in the medium severity category. The EPSS score is not available, so no current estimate of exploitation probability can be provided, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploits. Exploitation requires local authorized access, so the risk can be mitigated by limiting local administrative rights and promptly applying the vendor update.
OpenCVE Enrichment