Impact
The issue is an out‑of‑bounds read in the Windows Message Queuing Queue Manager that an unauthorized attacker can trigger over the network. When exploited the read causes the service to crash, resulting in a denial of service. The flaw is a classic buffer reading error (CWE‑125). No elevation of privilege or data disclosure is achieved, so the impact is limited to service unavailability for any application or user that relies on MSMQ.
Affected Systems
The vulnerability affects Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and server‑core installations.
Risk and Exploitability
The CVSS score of 7.5 signals a high severity flaw. While an EPSS score is not available, the vulnerability appears on a widely used messaging service that is exposed to the network, which suggests that a remote adversary could succeed in triggering it. The vulnerability is not yet listed in the CISA KEV catalog, but the lack of a current exploit metric does not diminish the need for proactive remediation.
OpenCVE Enrichment