Executive brief
A security vulnerability exists in the Windows DNS component, which is responsible for translating human-readable domain names into IP addresses. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt critical business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Windows DNS service. The vulnerability is triggered when the component improperly handles memory allocation during specific operations, allowing an attacker to overwrite adjacent memory. To exploit this, an attacker must first have local access to the system with low-level user privileges. Successful exploitation allows the attacker to execute code with elevated system privileges, potentially leading to a full compromise of the host. Microsoft has released security updates to address this issue across affected versions of Windows 10, 11, and Windows Server.
Affected products
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed: Initial advisory publication by Microsoft and NVD.