Microsoft Windows Message Queuing Heap-Based Buffer Overflow Remote Code Execution Vulnerability

Vulnerability

A heap-based buffer overflow vulnerability has been identified in Windows Message Queuing (MSMQ). This vulnerability allows an unauthorized attacker to execute code on a system over an adjacent network. The issue arises when MSMQ processes a specially crafted message, leading to memory corruption that can be exploited to run arbitrary code.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Remediation

Users can apply the security update for this vulnerability, which is included in the May 2026 security updates. Instructions for downloading the security update can be found in the Microsoft Update Catalog.

Added: May 12, 2026, 8:14 PM
Updated: May 12, 2026, 8:14 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
4.1
remediation
7.7
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.