Executive brief
Windows DNS is the domain name system component used by Windows to resolve hostnames to IP addresses on corporate networks. An authorized attacker could exploit a relative path traversal flaw to elevate their privileges from a standard user account to a higher level of system access, potentially gaining full control of affected systems.
Technical details
The vulnerability is a relative path traversal flaw in Windows DNS that allows an authorized attacker to achieve local privilege escalation. The attack requires existing authentication/authorization on the system but does not require network access or user interaction beyond the initial local access. By exploiting improper path handling, an attacker can read or manipulate DNS-related files outside their intended directory scope, leading to privilege escalation. Patches are expected to be available through Microsoft security updates.
Affected products
- Microsoft Windows DNS
Timeline
- 2026-08-11: disclosed