Junglewise Threat Intelligence

CVE-2026-65795: Microsoft Windows DNS relative path traversal privilege escalation

CVE-2026-65795 · Severity: medium · CVSS 6.7 · Published 2026-08-11

Technologies: Microsoft Windows DNS. Vendors: Microsoft.

Executive brief

Windows DNS is the domain name system component used by Windows to resolve hostnames to IP addresses on corporate networks. An authorized attacker could exploit a relative path traversal flaw to elevate their privileges from a standard user account to a higher level of system access, potentially gaining full control of affected systems.

Technical details

The vulnerability is a relative path traversal flaw in Windows DNS that allows an authorized attacker to achieve local privilege escalation. The attack requires existing authentication/authorization on the system but does not require network access or user interaction beyond the initial local access. By exploiting improper path handling, an attacker can read or manipulate DNS-related files outside their intended directory scope, leading to privilege escalation. Patches are expected to be available through Microsoft security updates.

Affected products

  • Microsoft Windows DNS

Timeline

  • 2026-08-11: disclosed

References

Related threats