Impact
The vulnerability is a relative path traversal flaw within the Windows DNS server component. An attacker who is authorized to use the DNS service can manipulate input to cause the server to write files outside its intended directories. By doing so, the attacker can drop malicious binaries or alter system configuration, effectively elevating their privileges on the local machine. The flaw provides a local privilege escalation path, enabling a compromised user to gain administrative control.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server 2016, 2019, 2022, 2025—including their Server Core installations.
Risk and Exploitability
The CVSS score of 6.7 denotes moderate severity, and the EPSS score of <1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA KEV, suggesting no widely publicized exploits currently. The attack vector is inferred to be local, requiring an authenticated or otherwise authorized user with access to the DNS service to elevate privileges on the host.
OpenCVE Enrichment