Impact
A heap‑based buffer overflow exists within the Windows DNS Server service. When the service processes maliciously crafted DNS data it can write beyond a buffer, allowing an attacker who already has local authorization to execute arbitrary code with the privileges of the DNS service, which normally runs as SYSTEM. This flaw enables an elevated privilege attack, potentially granting full local system access. The weakness aligns with CWE‑122, which describes uncontrolled memory corruption flaws.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1, along with Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including their Server Core variants) are affected. All listed releases run on the specified architecture families (x86, x64, arm64).
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, and the EPSS score of <1% suggests a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers must have local authorization to modify DNS data, so the attack vector is local. Despite the low probability, the potential impact of reaching SYSTEM privileges warrants careful attention.
OpenCVE Enrichment