Impact
A heap‑based buffer overflow flaw exists in the Windows Message Queuing (MSMQ) service that allows an unauthenticated attacker to execute arbitrary code on any host that exposes MSMQ over a network. The overflow occurs when the service processes malformed queue messages, leading to full control over the affected system with potential to install malware, exfiltrate data, or pivot to other internal resources. The vulnerability is strongly coupled with the CWE‑122 category, underscoring the classic heap misuse and the severe consequences for confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows operating systems are affected. Clients include Windows 10 builds 1607, 1809, 21H2, and 22H2, as well as Windows 11 builds 24H2, 25H2, and 26H1; all are supported on x86, x64, and ARM64 architectures. Server deliveries span Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both Standard and Server Core installations. Any system that has the MSMQ service enabled is potentially vulnerable.
Risk and Exploitability
The CVSS v3 score of 9.8 indicates critical severity, while the EPSS score of less than 1% reflects a very low current exploitation probability; however, the lack of listing in the CISA KEV catalog does not mitigate the high impact of a successful exploit. The likely attack vector is a remote network approach, where an attacker sends specially crafted MSMQ messages to the target service. The vulnerability can be leveraged without privileged credentials, provided the attacker can reach the MSMQ windows service port. Given the breadth of affected platforms, the exploitation surface is wide, and an organization should treat this as an enterprise‑wide threat.
OpenCVE Enrichment