Junglewise Threat Intelligence

CVE-2026-65799: Microsoft Windows DNS integer overflow privilege escalation

CVE-2026-65799 · Severity: medium · CVSS 6.7 · Published 2026-08-11

Executive brief

Windows DNS is a critical networking service that resolves domain names to IP addresses across enterprise environments. An authorized local attacker can exploit an integer overflow vulnerability to escalate their privileges on affected systems, potentially gaining administrative access and compromising system security.

Technical details

An integer overflow or wraparound vulnerability exists in the Windows DNS service, allowing a local attacker with valid credentials to escalate privileges. The vulnerability is in the DNS service component and requires the attacker to already have local system access. Exploitation of this flaw enables privilege escalation from a standard user account to SYSTEM or administrative level, compromising the confidentiality and integrity of the affected system. A security patch is available from Microsoft.

Affected products

  • Microsoft Windows DNS

Timeline

  • 2026-08-11: disclosed

References

Related threats