Impact
A heap buffer overflow occurs when the queue manager processes MQPUT operations that contain malformed distribution headers. An authenticated attacker who can send such requests can trigger the overflow, which may result in a denial of service by crashing the service or in a privilege escalation if memory corruption is exploited during processing.
Affected Systems
IBM MQ 9.1 LTS up to 9.1.0.37; IBM MQ 9.2 LTS up to 9.2.0.43; IBM MQ 9.3 LTS up to 9.3.5.1; IBM MQ 9.4 LTS up to 9.4.5.1; IBM MQ 10.0.0.0.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS score of 0.00477 (0.477%) indicates a very low but nonzero exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog, implying no confirmed public exploits so far. The attack requires authentication to the queue manager, so an attacker must possess legitimate credentials or compromise an existing user. Based on the description, it is inferred that the attacker must be authenticated to the queue manager and can send specially crafted MQPUT requests, which will overflow a heap buffer, crash the service or elevate privileges, potentially enabling wider compromise of the host.
OpenCVE Enrichment