Impact
A heap‑based buffer overflow exists in the Windows Message Queuing subsystem that enables an attacker who already has local access to the target machine to gain higher privileges. The flaw can be triggered by sending a specially crafted message to the queuing service, causing an overflow of a heap buffer managed by the service. The vulnerability is a classic example of CWE‑122 and can be exploited only by users who can invoke the Message Queuing API locally, thus the impact is confined to local privilege escalation rather than remote exploitation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including both full and Server Core installations. All affected releases run the vulnerable Message Queuing service unless patched.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level, while the EPSS score of less than 1% reflects a low probability that the vulnerability is being widely exploited in the wild. This vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local – an attacker who can run code on the system to call the Message Queuing service can craft data that causes the overflow. No remote or network‑based attack vector is documented.
OpenCVE Enrichment