Impact
IBM MQ .NET client has a heap buffer overflow that can be triggered when the client receives a message from a malicious queue manager or via a man‑in‑the‑middle. The overwrite allows the attacker to cause a denial of service or, if exploited, to execute arbitrary code on the client host. This flaw is an out‑of‑bounds write, identified as CWE‑787.
Affected Systems
The vulnerability affects IBM MQ LTS releases 9.1, 9.2, 9.3, and 9.4, specifically versions 9.1.0.0‑9.1.0.37, 9.2.0.0‑9.2.0.43, 9.3.0.0‑9.3.0.41 and 9.3.5.1 CD, 9.4.0.0‑9.4.0.25 and 9.4.5.1 CD, as well as the 10.0.0.0 baseline and all earlier 10.x releases up to 10.0.0.5. All of these installations run the IBM MQ .NET client and are susceptible to the overflow.
Risk and Exploitability
The CVSS score of 8.1 signifies high severity, while the EPSS score of less than 1 % suggests a low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no widely observed attacks yet. Nevertheless, the flaw is reachable from outside the trusted network, requires no special privileges, and can lead to denial of service or arbitrary code execution on is essential.
OpenCVE Enrichment