Impact
The vulnerability is a numeric truncation error in the Windows DNS service. This flaw lets an attacker who already has authorized local access bump their privileges throughout the system. The flaw arises from improper handling of numeric values in DNS queries, and the CWE identifiers indicate a buffer overread or truncation issue (CWE-122) and numeric conversion problems (CWE-197). Because the elevation occurs locally, it can compromise the entire OS once the attacker gains SYSTEM level, enabling full control over files, registry, processes, and other resources.
Affected Systems
Microsoft Windows computers running Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and Server Core installations. All listed builds, whether 32‑bit or 64‑bit, are susceptible. Administrators should consult the Microsoft update guide to confirm patch status for each affected build.
Risk and Exploitability
The CVSS score of 6.7 places the flaw in the medium severity bracket, but the local nature means only users with some degree of authorization can exploit it. The EPSS score is not available, so the current availability of exploitation tools is unclear. The vulnerability is not in the CISA KEV catalog, which reduces the expectation of widespread exploitation. However, because it provides local privilege escalation—a pivot point for executing arbitrary code—organizations should treat it with urgency, especially if any host carries unpatched Windows DNS services or has high‑value accounts that could be leveraged locally.
OpenCVE Enrichment