Impact
Relative path traversal is present in the Windows DNS service, allowing an attacker with local authorization to manipulate file paths and access files that should be protected, thereby enabling privilege escalation on the host. The weakness is classified as CWE-23.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, Windows Server 2012 (including Server Core installation), Windows Server 2012 R2 (including Server Core installation), Windows Server 2016 (including Server Core installation), Windows Server 2019 (including Server Core installation), Windows Server 2022, Windows Server 2025 (including Server Core installation) are affected by the path traversal flaw in the DNS service without a patch.
Risk and Exploitability
The CVSS score of 6.7 indicates medium severity and the vulnerability is not listed in CISA KEV, with no EPSS score available, implying limited or undetected exploitation so far. The likely attack vector is a locally authorized user or account that can interact with the DNS service; such an attacker can exploit the missing path validation to elevate privileges on the system.
OpenCVE Enrichment