Record summary

CVE-2026-62883 has a selected CVSS score of 6.7 (medium).

Description

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 7, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 19
ProductSourceVersion rangeStatus
CVE List10.0.14393.0 to < 10.0.14393.9418affected
CVE List10.0.17763.0 to < 10.0.17763.9115affected
CVE List10.0.19044.0 to < 10.0.19044.7663affected
CVE List10.0.19045.0 to < 10.0.19045.7663affected
CVE List10.0.22631.0 to < 10.0.22631.7517affected
CVE List10.0.26100.0 to < 10.0.26100.9168affected
CVE List10.0.26200.0 to < 10.0.26200.9168affected
CVE List10.0.28000.0 to < 10.0.28000.2704affected
CVE List6.2.9200.0 to < 6.2.9200.26280affected

Windows Server 2012 (Server Core installation)

Browse Microsoft / Windows Server 2012 (Server Core installation)
CVE List6.2.9200.0 to < 6.2.9200.26280affected
CVE List6.3.9600.0 to < 6.3.9600.23338affected

Windows Server 2012 R2 (Server Core installation)

Browse Microsoft / Windows Server 2012 R2 (Server Core installation)
CVE List6.3.9600.0 to < 6.3.9600.23338affected

References

2