Executive brief
A security vulnerability in the Windows DNS component could allow a user who already has basic access to a computer to tamper with system settings. This could lead to a disruption of network services or the redirection of internet traffic to malicious sites. While the attacker must already be logged into the system, the impact on the reliability and integrity of the network configuration is significant.
Technical details
An improper access control vulnerability (CWE-284) exists in the Microsoft Windows DNS component. A locally authenticated attacker with low privileges can exploit this flaw to tamper with DNS configurations without requiring administrative rights or user interaction. Successful exploitation could result in a loss of integrity and availability, potentially allowing the attacker to disrupt name resolution or redirect traffic. The vulnerability affects several modern versions of Windows 11 and Windows Server 2025, and Microsoft has released security updates to address the issue.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory