Junglewise Threat Intelligence

CVE-2026-72948: Microsoft Windows DNS relative path traversal privilege escalation

CVE-2026-72948 · Severity: medium · CVSS 6.7 · Published 2026-09-08

Executive brief

Windows DNS Server contains a flaw that allows an authenticated local user to manipulate file paths and gain elevated privileges on the system. An attacker with standard user access could exploit this to run commands with administrator rights, potentially compromising the entire server and any dependent infrastructure.

Technical details

A relative path traversal vulnerability exists in the Windows DNS service that can be exploited by an authorized local user to escalate privileges. The vulnerability stems from improper handling of file path validation in the DNS component, allowing an attacker to reference files outside the intended directory scope. Exploitation requires local access and prior authentication to the system, but does not require user interaction. A successful exploit grants the attacker administrative or system-level privileges, enabling full system compromise. A patch is available from Microsoft.

Affected products

  • Microsoft Windows DNS

Timeline

  • 2026-09-08: disclosed

References

Related threats