Executive brief
Windows DNS, a core service that translates domain names to IP addresses on Windows systems, contains an out-of-bounds read vulnerability. An authenticated local attacker can exploit this flaw to read sensitive information from system memory, potentially exposing credentials or other confidential data.
Technical details
An out-of-bounds read vulnerability exists in Windows DNS service, allowing an authorized local attacker to access memory beyond the intended buffer boundaries. The vulnerability requires local access and authentication, limiting its attack surface to users with local system privileges. Exploitation permits information disclosure from DNS service memory, which may contain sensitive configuration data or cached credentials. Microsoft has released security updates to patch this vulnerability as indicated by the CVE publication.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed