Impact
The vulnerability is a use‑after‑free flaw in the Microsoft Message Queuing Queue Manager. An attacker who can connect to the Queue Manager can send specially crafted data that causes the manager to free memory after it is no longer safe to use, allowing the attacker to execute arbitrary code on the affected system. The flaw, identified as CWE‑416, enables remote code execution and therefore compromise of the confidentiality, integrity, and availability of the system.
Affected Systems
The flaw affects Microsoft Windows operating systems, including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server (2012, 2012 R2, 2016, 2019, 2022, 2025). Both client and server editions, including Server Core installations, that have the Message Queuing service running are potentially vulnerable. No specific build or patch level is listed beyond the versions enumerated by Microsoft in the CNA product list.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score of less than 1 % suggests that it is currently unlikely to be widely exploited, and it is not listed in the CISA KEV catalog. Nevertheless, the attack vector is inferred to be remote over the network to the Queue Manager service; an unauthenticated attacker can trigger the use‑after‑free and gain code‑execution privileges, which could be leveraged to pivot inside a network or modify system configuration. Given the high impact and potential for privilege escalation, the risk warrants prompt mitigation.
OpenCVE Enrichment