Impact
This vulnerability is an origin validation error in Windows DNS that allows an unauthorized attacker on the same network to forge DNS responses. By bypassing normal origin checks, the attacker can manipulate client name resolution so that traffic is directed to malicious servers, thereby compromising confidentiality and integrity of the affected systems. The flaw is classified as CWE-346, a flaw that permits an attacker to make a system believe it is communicating with a legitimate entity.
Affected Systems
Affected systems include Microsoft Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012, Windows Server 2012 Server Core, Windows Server 2012 R2, Windows Server 2012 R2 Server Core, Windows Server 2016, Windows Server 2016 Server Core, Windows Server 2019, Windows Server 2019 Server Core, Windows Server 2022, Windows Server 2025, and Windows Server 2025 Server Core.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. EPSS is not available, but it is inferred from the official Microsoft advisory that attackers may be prepared to exploit the flaw. The vulnerability is not listed in CISA KEV catalog, suggesting no confirmed active exploitation yet. The required attack vector is network‑based; an attacker must be able to send forged DNS responses over the local network and no authentication is required.
OpenCVE Enrichment