Impact
Heap-based buffer overflow in Windows Message Queuing permits an authorized local attacker to gain elevated privileges. The flaw stems from improper bounds checking in the Message Queuing service, classed as CWE-122. Executing the overflow allows a malicious user to subvert the security model and run code with higher privileges than they originally possessed.
Affected Systems
Microsoft Windows 10 versions 1607 through 22H2, Windows 11 versions 23H2 through 26H1, and Windows Server editions from 2012 to 2025 are affected. The vulnerability is present in both full and server‑core installations of the listed OS releases.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity, while the EPSS score of less than 1% reflects a low probability of exploitation. The flaw requires local, authorized access and has not been listed in the CISA KEV catalog, suggesting no known widespread exploitation. Nevertheless, because privilege escalation can enable further attacks, the risk to systems remains significant whenever a user can interact with the Message Queuing service.
OpenCVE Enrichment