Junglewise Threat Intelligence

CVE-2026-69672: Microsoft Windows DNS information disclosure via uninitialized resource

CVE-2026-69672 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Windows DNS, a core networking service used to resolve domain names and manage DNS queries across Windows environments, contains a flaw that allows an authorized local user to read sensitive information from memory. An attacker with local access could exploit this to extract data such as DNS queries, cached records, or other sensitive information that should remain confidential.

Technical details

The vulnerability is a use-of-uninitialized-resource (CWE-908) flaw in the Windows DNS service. An authorized attacker with local system access can trigger the uninitialized resource to disclose information resident in memory. The attack requires local access and existing authorization on the system—no network-based exploitation is possible. By leveraging this weakness, an attacker could read sensitive data stored by the DNS service without elevated privileges. Microsoft has released a security patch to initialize resources properly before use.

Affected products

  • Microsoft Windows DNS <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats