CVE-2026-49174
Analyzed Analyzed - Analysis Complete

Missing Authentication in Windows DNS Allows Local Tampering

Vulnerability report for CVE-2026-49174, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 17 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-49174 is a vulnerability in Microsoft Windows DNS where a critical function lacks proper authentication. This means that an authorized attacker with local access to the system can exploit this flaw to tamper with DNS operations or configurations.

The vulnerability is classified as a tampering issue, meaning the attacker can modify data or system behavior without proper authorization. The CVSS v3.1 score of 6.1 indicates a medium severity, with the attack vector being local (AV:L), low attack complexity (AC:L), and requiring low privileges (PR:L).

Detection Guidance

Detection requires checking for unauthorized DNS modifications or unusual local tampering activities. Monitor DNS server logs for unexpected changes and verify authentication mechanisms are enforced. No specific commands are provided in the available resources.

Impact Analysis

This vulnerability can impact you in several ways if exploited by an attacker with local access to your system:

  • Tampering with DNS settings: An attacker could modify DNS records, redirecting network traffic to malicious servers, leading to phishing attacks or data interception.
  • Disruption of network services: Changes to DNS configurations could cause service outages or misrouting of legitimate traffic, affecting business operations.
  • Data integrity risks: Tampering with DNS could allow attackers to manipulate how data is resolved or transmitted, potentially leading to unauthorized access or data corruption.

Since the vulnerability requires local access, the risk is higher in environments where multiple users or systems share access, such as enterprise networks or shared workstations.

Compliance Impact

This vulnerability could affect compliance with several standards and regulations, depending on the context of its exploitation:

  • GDPR (General Data Protection Regulation): If DNS tampering leads to unauthorized access or exposure of personal data, it could violate GDPR requirements for data protection and confidentiality. Organizations may face penalties for failing to secure personal data adequately.
  • HIPAA (Health Insurance Portability and Accountability Act): In healthcare environments, tampering with DNS could result in unauthorized access to protected health information (PHI). This would violate HIPAA's security and privacy rules, leading to potential fines or legal consequences.
  • Other standards (e.g., ISO 27001, NIST): Many compliance frameworks require organizations to implement access controls and authentication mechanisms for critical functions. This vulnerability represents a failure to meet such requirements, potentially resulting in non-compliance.

Organizations should assess the risk posed by this vulnerability and apply patches or mitigations to maintain compliance with relevant regulations.

Mitigation Strategies

The provided context does not include specific mitigation steps for CVE-2026-49174. However, general steps to address missing authentication for critical functions in Microsoft Windows DNS may include:

  • Apply the latest security updates from Microsoft as soon as they are available. Check the Microsoft Update Guide for patches related to this CVE.
  • Restrict local access to the DNS server to only authorized users and processes to reduce the risk of exploitation.
  • Monitor Microsoft's official communications for any additional guidance or workarounds related to this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49174. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart