Junglewise Threat Intelligence

CVE-2026-50465: Microsoft Windows DNS improper access control tampering

CVE-2026-50465 · Severity: high · CVSS 7.1 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 24H2, Microsoft Windows Server 2025, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability in the Windows DNS component could allow a user who already has basic access to a computer to tamper with system settings. This could lead to a disruption of network services or the redirection of internet traffic to malicious sites. While the attacker must already be logged into the system, the impact on the reliability and integrity of the network configuration is significant.

Technical details

An improper access control vulnerability (CWE-284) exists in the Microsoft Windows DNS component. A locally authenticated attacker with low privileges can exploit this flaw to tamper with DNS configurations without requiring administrative rights or user interaction. Successful exploitation could result in a loss of integrity and availability, potentially allowing the attacker to disrupt name resolution or redirect traffic. The vulnerability affects several modern versions of Windows 11 and Windows Server 2025, and Microsoft has released security updates to address the issue.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats