Impact
Windows Message Queuing contains a heap‒based buffer overflow that can be triggered by an authenticated local user. When the overflow occurs, the trusted process handling the message queue can be corrupted, allowing the attacker to gain higher privileges on the affected system. The flaw does not expose data externally but enables privilege escalation, potentially compromising the entire operating system.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. Both server core and full image installations are impacted.
Risk and Exploitability
The CVSS score of 7.8 denotes high impact. The EPSS score of less than 1% indicates low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers need local authorized access, and no known remote exploitation vector exists. Nevertheless, any privileged user or group that can interact with the message queue service could exploit the flaw to run code with elevated rights.
OpenCVE Enrichment