Junglewise Threat Intelligence

CVE-2026-65797: Microsoft Windows DNS numeric truncation privilege escalation

CVE-2026-65797 · Severity: medium · CVSS 6.7 · Published 2026-08-11

Technologies: Microsoft Windows DNS Server. Vendors: Microsoft.

Executive brief

Windows DNS Server contains a numeric truncation error that allows an authenticated local attacker to escalate privileges on the system. An attacker with valid credentials could exploit this flaw to gain elevated system rights, potentially compromising the security of the entire domain infrastructure that relies on the DNS server.

Technical details

A numeric truncation error exists in the Windows DNS Server component that permits privilege escalation through local attack. The vulnerability requires the attacker to have valid credentials and local access to the affected system. The root cause is improper handling of numeric values leading to truncation, which can be leveraged to bypass privilege checks. An authenticated local attacker can exploit this flaw to gain SYSTEM-level privileges. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows DNS Server

Timeline

  • 2026-08-11: disclosed

References

Related threats