Impact
The vulnerability stems from an uninitialized resource within the Windows DNS server. An attacker with local privileges can read that resource and learn confidential data that the service holds, resulting in sensitive information disclosure. This weakness is classified as CWE‑908, an uninitialized resource issue.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607 and 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, both in full and Server Core installations. The vulnerability is present across these operating systems, making it widely applicable to Windows environments that run the built‑in DNS service.
Risk and Exploitability
The CVSS score of 5.5 places this error in the moderate severity range, and the absence of an EPSS score coupled with its current absence from the CISA KEV catalog indicates no known exploitation in the wild. Because the flaw requires local authorization, attackers need at least standard user or higher privileges, but once they gain access they could read potentially sensitive DNS data, threatening confidentiality. Administrators should treat the issue as a significant local vulnerability.
OpenCVE Enrichment