Executive brief
A vulnerability in the Microsoft Windows DNS Server component could allow an authorized user to execute malicious code on the server. The DNS Server is a critical piece of infrastructure that translates human-readable web addresses into IP addresses. If exploited, an attacker could gain full control over the server, potentially leading to data theft or significant network disruption.
Technical details
A relative path traversal vulnerability (CWE-23) exists in the Microsoft Windows DNS Server. The flaw allows an attacker with high privileges (PR:H) to bypass directory restrictions and execute arbitrary code. The attack vector is limited to the adjacent network (AV:A), meaning the attacker must be on the same local network or subnet as the target server. Successful exploitation grants the attacker full system access (Confidentiality, Integrity, and Availability impact). Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 Version 1607 < 10.0.14393.9339
- Microsoft Windows 10 Version 1809 < 10.0.17763.9020
- Microsoft Windows Server 2012 / 2012 R2 Server 2012 < 6.2.9200.26226; Server 2012 R2 < 6.3.9600.23291
- Microsoft Windows Server 2016 / 2019 Server 2016 < 10.0.14393.9339; Server 2019 < 10.0.17763.9020
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory