Impact
A numeric truncation flaw in the Windows DNS service permits a local attacker with authorized access to gain elevated privileges on the host. Once exploited, the attacker can execute arbitrary code, modify system configuration, or install malware at an elevated privilege level, potentially compromising the entire machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including core installations.
Risk and Exploitability
The CVSS score of 6.7 indicates non‑critical but still real risk. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, so exact exploit probability is unclear. The flaw is exploitable only by a local user who can influence DNS service inputs, meaning an attacker must have local or administrative access to the affected machines.
OpenCVE Enrichment