CVE-2026-70304: Windows DNS Elevation of Privilege Vulnerability
Published Aug 11, 2026
·Updated
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Other sources
Windows DNS Elevation of Privilege Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Windows DNS
Event History
Aug 11, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionSeverity
Data Sourced
via NVD·05:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-70304?
CVE-2026-70304 has a medium severity score of 6.7.
2
How does CVE-2026-70304 affect Microsoft Windows DNS?
CVE-2026-70304 creates a buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally.
3
What type of vulnerability is CVE-2026-70304 classified as?
CVE-2026-70304 is classified as a buffer overflow vulnerability.
4
What is required for an attacker to exploit CVE-2026-70304?
An attacker must have authorized access to the affected system to exploit CVE-2026-70304.
5
When was CVE-2026-70304 published?
CVE-2026-70304 was published on August 11, 2026.