Impact
This vulnerability is a classic use‑after‑free flaw in Windows Message Queuing that permits an authorized local attacker to gain elevated privileges on the affected system. Because the flaw permits a local subject to bypass the normal permission checks within the MQ kernel process, the attacker can potentially raise the process’ token to act with administrative authority, thereby compromising the confidentiality, integrity, and availability of data and services on the host. The weakness is identified as CWE‑416 and is limited to operations performed by a local, authenticated user exfiltrating control over the MQ infrastructure.
Affected Systems
Affected systems are Microsoft Windows operating systems including Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and a range of Windows Server releases from Server 2012 through Server 2025. No specific sub‑versions or patch levels are excluded, so all installations of these OS releases are considered vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability; however, an exploit requires local authenticated access, meaning only users with existing privileges can take advantage of the flaw. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed public exploitation yet. Attackers would target the Message Queuing service on the local host, potentially leveraging existing administrative tools or custom code to trigger the freed memory reference and elevate privileges.
OpenCVE Enrichment