Microsoft Windows DNS Improper Access Control Vulnerability Allowing Local Tampering

Vulnerability

A vulnerability has been identified in Microsoft Windows DNS that involves improper access control. This flaw allows an authorized attacker to manipulate DNS settings or data locally. The issue arises from inadequate restrictions on user permissions, enabling unauthorized modifications by users with certain privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized tampering with DNS data or settings, potentially disrupting network services or causing misdirection of network traffic.

Remediation

Users can apply the security update for this vulnerability through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5101649 for Windows 11 Version 26H1 (ARM64 and x64), KB5099536 for Windows Server 2025, and KB5101650 for Windows 11 Versions 24H2 and 25H2 (both ARM64 and x64).

Added: Jul 14, 2026, 11:04 PM
Updated: Jul 14, 2026, 11:04 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
3.3
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.