Microsoft Message Queuing Queue Manager Use-After-Free Vulnerability Allowing Remote Code Execution

Vulnerability

A use-after-free vulnerability has been identified in the Microsoft Message Queuing Queue Manager. This vulnerability allows an unauthorized attacker to execute code remotely over the network. It affects multiple Windows versions, including various Windows 10 releases, Windows 11, Windows Server 2012, 2016, 2019, 2022, and 2025, as well as Windows Server 2012 R2 and 2025 Server Core installations.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Remediation

Users can apply the security update for this vulnerability, which is included in the July 2026 Monthly Rollup, available through the Microsoft Update Catalog.

Added: Jul 15, 2026, 6:39 AM
Updated: Jul 15, 2026, 6:39 AM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
6.4
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.