Executive brief
A vulnerability in the Windows DNS component could allow a user who already has access to a computer to tamper with its DNS settings. This could allow an attacker to redirect network traffic or disrupt how the computer finds services on the internet or local network. While it requires local access to the machine, it poses a risk to the integrity of network communications on affected Windows and Windows Server systems.
Technical details
An improper access control vulnerability (CWE-284) exists in the Microsoft Windows DNS component. A locally authenticated attacker with low privileges can exploit this flaw to perform unauthorized tampering with DNS configurations. The vulnerability does not require user interaction and has a high impact on system integrity, though it has low impact on availability and no impact on confidentiality. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates made available by Microsoft