Impact
Heap-based buffer overflow in the Windows DNS Server component enables an attacker who already has local user privileges to elevate their level of control. When triggered, the flaw can let the malicious process write arbitrary data to the heap, potentially allowing the execution of privileged code or manipulation of DNS resolution behavior. The vulnerability is identified as CWE‑122, a classic heap corruption weakness.
Affected Systems
Microsoft Windows 10 platforms from version 1607 through 22H2 and Windows 11 from 23H2 to 26H1 are vulnerable. The flaw also affects Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and core installation variants.
Risk and Exploitability
The CVSS score of 6.7 categorizes the issue as moderate severity. EPSS indicates an exploitation probability of less than 1 %, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires local, authenticated access, threat actors would need to compromise a user account or application before attempting exploitation. Applying the patched update is the most effective defense, as there is presently no widely documented public exploit yet.
OpenCVE Enrichment