Junglewise Threat Intelligence

CVE-2026-65798: Windows DNS numeric truncation privilege escalation

CVE-2026-65798 · Severity: medium · CVSS 6.7 · Published 2026-08-11

Executive brief

Windows DNS is a critical component that resolves domain names to IP addresses across Windows networks. A numeric truncation error in this service allows an attacker with local access and administrative credentials to elevate their privileges further on the system, potentially compromising system integrity and administrative control.

Technical details

A numeric truncation error exists in Windows DNS service that can be exploited to achieve local privilege escalation. The vulnerability requires an authorized user (with existing login credentials) to trigger the flaw through a specially crafted request. The attack vector is local; network-accessible exploitation is not indicated. An attacker who successfully exploits this vulnerability can escalate their privileges on the affected system. Microsoft has released patches to address this vulnerability; administrators should apply the available security updates promptly.

Affected products

  • Microsoft Windows DNS <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats