6.8

CVE-2026-50426

Windows DNS Server Remote Code Execution Vulnerability

Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWindows 10 1607 HwPlatformx64 Version < 10.0.14393.9339
MicrosoftWindows 10 1607 HwPlatformx86 Version < 10.0.14393.9339
MicrosoftWindows 10 1809 HwPlatformx64 Version < 10.0.17763.9020
MicrosoftWindows 10 1809 HwPlatformx86 Version < 10.0.17763.9020
MicrosoftWindows Server 2016 Version < 10.0.14393.9339
MicrosoftWindows Server 2019 Version < 10.0.17763.9020
MicrosoftWindows Server 2022 Version < 10.0.20348.5386
MicrosoftWindows Server 2025 Version < 10.0.26100.33158
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.283
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 6.8 0.9 5.9
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-23 Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50426
Patch
Vendor Advisory