CVE-2026-58275
10.0Microsoft · Azure DNS
A missing authorization vulnerability in Microsoft Azure DNS allows unauthenticated, remote attackers to escalate privileges over a network.
Executive summary
Microsoft Azure DNS contains a critical missing authorization flaw that permits unauthenticated, remote attackers to escalate privileges and disrupt service availability.
Vulnerability
This vulnerability is caused by missing authorization (CWE-862) within Microsoft Azure DNS. It allows an unauthenticated attacker to perform actions they are not permitted to execute, facilitating privilege escalation.
Business impact
With a CVSS score of 10.0, this vulnerability poses a severe threat to infrastructure integrity. An attacker could modify critical DNS configurations, leading to traffic redirection, man-in-the-middle attacks, or complete denial-of-service for dependent network services, resulting in significant operational downtime.
Remediation
Immediate Action: Consult the Microsoft Security Response Center update guide and apply the most recent security patches for Azure DNS.
Proactive Monitoring: Review DNS configuration audit logs for unauthorized changes and monitor for unexpected service disruptions.
Compensating Controls: Utilize Azure Policy to restrict unauthorized modifications to DNS resources and ensure that access control lists are configured to the principle of least privilege.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
The potential for widespread disruption to network traffic makes this a high-priority remediation task. Organizations should apply the vendor-provided patches immediately and perform a thorough audit of their Azure DNS configurations to ensure no unauthorized modifications have occurred.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Fix documented per CVE record