CVE-2026-58275

10.0

Microsoft · Azure DNS

A missing authorization vulnerability in Microsoft Azure DNS allows unauthenticated, remote attackers to escalate privileges over a network.

Executive summary

Microsoft Azure DNS contains a critical missing authorization flaw that permits unauthenticated, remote attackers to escalate privileges and disrupt service availability.

Vulnerability

This vulnerability is caused by missing authorization (CWE-862) within Microsoft Azure DNS. It allows an unauthenticated attacker to perform actions they are not permitted to execute, facilitating privilege escalation.

Business impact

With a CVSS score of 10.0, this vulnerability poses a severe threat to infrastructure integrity. An attacker could modify critical DNS configurations, leading to traffic redirection, man-in-the-middle attacks, or complete denial-of-service for dependent network services, resulting in significant operational downtime.

Remediation

Immediate Action: Consult the Microsoft Security Response Center update guide and apply the most recent security patches for Azure DNS.

Proactive Monitoring: Review DNS configuration audit logs for unauthorized changes and monitor for unexpected service disruptions.

Compensating Controls: Utilize Azure Policy to restrict unauthorized modifications to DNS resources and ensure that access control lists are configured to the principle of least privilege.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

The potential for widespread disruption to network traffic makes this a high-priority remediation task. Organizations should apply the vendor-provided patches immediately and perform a thorough audit of their Azure DNS configurations to ensure no unauthorized modifications have occurred.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Fix documented per CVE record