Impact
An integer overflow or wraparound flaw in the Windows DNS server allows an authenticated local attacker to craft DNS packets that elevate the service’s privileges. The bug is expressed by CWE-122 and CWE-190. The result is that a user with limited rights can gain system or administrative access, jeopardizing confidentiality, integrity, and availability of the entire machine.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1) and the corresponding Server releases (Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 including Server Core builds).
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity. No EPSS value is reported, and the vulnerability is not listed in CISA’s KEV catalog, meaning public exploitation evidence is limited. The likely attack vector is local; an attacker must already have some level of access to the target machine to trigger the overflow and elevate privileges.
OpenCVE Enrichment