Impact
A use‑after‑free flaw in Windows Message Queuing allows an attacker to trigger arbitrary code execution on a target system. The vulnerability arises when the message queue service incorrectly reuses a freed memory object, enabling the attacker to craft malicious messages that are processed with elevated privileges. The flaw is identified by CWE-416 and can be leveraged by an adversary with network access to the Message Queuing service.
Affected Systems
Affected Windows operating systems include Windows 10 21H2 and 22H2, Windows 11 23H2 through 26H1, Windows Server 2022, and Windows Server 2025 (including Server Core). The issue applies to various processor architectures such as x86, x64, and arm64.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is not available, making it unclear how frequently this weakness is exploited. The vulnerability is not listed in CISA's KEV catalog. Attackers can exploit the flaw remotely via the Message Queuing protocol from a network location that can reach the Windows service. No special privileges or user interaction are required, making the potential impact immediate if the queue is exposed to untrusted hosts.
OpenCVE Enrichment