Junglewise Threat Intelligence

CVE-2026-49174: Microsoft Windows DNS missing authentication in critical function

CVE-2026-49174 · Severity: medium · CVSS 6.1 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows DNS component, which is responsible for translating human-readable website names into computer-readable addresses. An attacker who already has basic access to a computer could exploit this flaw to modify DNS settings or data without proper authorization. This could allow an attacker to redirect network traffic or interfere with how the system communicates with other services on the network.

Technical details

A missing authentication vulnerability (CWE-306) exists in the Microsoft Windows DNS component. The flaw allows a locally authenticated attacker with low privileges to bypass security checks and execute critical functions that should require higher authorization. By exploiting this, an attacker can perform tampering of DNS-related data or configurations. The attack vector is local, meaning the attacker must already have the ability to execute code on the target system. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD.
  • 2026-07-14: advisory: Microsoft Security Update Guide published.

References

Related threats