Impact
Buffer over-read in the Windows Message Queuing Queue Manager can be triggered by sending specially crafted network messages. The flaw allows an attacker with network access to read beyond the intended buffer boundaries, exposing sensitive data that resides in memory. This vulnerability is classified as CWE-126 and results in the disclosure of information without authentication or elevation of privileges, potentially leaking confidential credentials or system secrets.
Affected Systems
The flaw affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and multiple Windows Server releases including 2012, 2012 R2, 2016, 2019, 2022 and 2025, with both full and Server‑Core installations. Any system with the Message Queuing service enabled is potentially vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 7.5 places the vulnerability in the high‑severity range, and the lack of an authentication requirement means a remote attacker can exploit it from any machine that can reach the MSMQ service over the network. The EPSS score of 1% indicates a low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, but the high severity and network reachability make it a significant threat. An attacker could use this flaw to gather sensitive data, with a high likelihood in environments where MSMQ is exposed to untrusted networks.
OpenCVE Enrichment