Description
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker exploiting a use‑after‑free bug in the Windows Message Queuing (MSMQ) implementation can cause the system to execute arbitrary code. Once the vulnerable memory region is reused, malicious input can be injected to alter program behavior, allowing the attacker to gain arbitrary code execution on the compromised host. The flaw enables control over the affected machine’s memory management, potentially leading to privilege escalation, data theft, or system disruption. The weakness corresponds to CWE-416, where an object is destroyed and then accessed.

Affected Systems

The vulnerability affects multiple Microsoft Windows operating systems as identified by the CNA. Clients running Windows 10 build 1607, 1809, 21H2, or 22H2, and Windows 11 build 23H2, 24H2, 25H2, or 26H1 are susceptible. It also affects server editions: Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full installations and Server Core deployments. Each of these OS versions contains the MSMQ service component that is vulnerable.

Risk and Exploitability

The CVSS base score of 9.8 indicates a high‑severity remote code execution potential. EPSS data is unavailable, but the lack of listing in the CISA KEV catalog does not diminish the risk of exploitation. The attack is likely carried out remotely over the network, as stated in the description, by sending specifically crafted MSMQ messages to the target. Once the use‑after‑free condition is triggered, the attacker can execute arbitrary code with the privileges of the MSMQ service, which may then be leveraged for further compromise.

Generated by OpenCVE AI on September 8, 2026 at 22:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE‑2026‑69579 to all affected Windows and server editions.
  • Temporarily disable the Windows Message Queuing service on systems where patching cannot be performed immediately.
  • Restrict inbound network traffic to the MSMQ service using firewall or network segmentation until the fix is in place.

Generated by OpenCVE AI on September 8, 2026 at 22:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Title Windows Message Queuing Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:36:26.700Z

Reserved: 2026-08-03T21:18:49.122Z

Link: CVE-2026-69579

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:27.440

Modified: 2026-09-08T18:39:34.660

Link: CVE-2026-69579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T23:00:13Z

Weaknesses