Описание
Windows Zero Trust DNS Security Feature Bypass Vulnerability
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
FAQ
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Zero Trust DNS (ZTDNS) policy enforcement.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Windows 11 Version 24H2 for ARM64-based Systems | ||
| Windows 11 Version 24H2 for x64-based Systems | ||
| Windows Server 2025 | ||
| Windows Server 2025 (Server Core installation) | ||
| Windows 11 Version 25H2 for ARM64-based Systems | ||
| Windows 11 Version 25H2 for x64-based Systems | ||
| Windows 11 version 26H1 for x64-based Systems | ||
| Windows 11 Version 26H1 for ARM64-based Systems |
Показывать по
10
Возможность эксплуатации
Publicly Disclosed
No
Exploited
No
Latest Software Release
Exploitation Less Likely
EPSS
Процентиль: 13%
0.00222
Низкий
5.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.5
nvd
16 дней назад
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
CVSS3: 5.5
github
16 дней назад
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
EPSS
Процентиль: 13%
0.00222
Низкий
5.5 Medium
CVSS3