Executive brief
A security vulnerability exists in the Windows Message Queuing service, which is used for reliable communication between applications. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to view sensitive data, install programs, or disrupt business operations on the affected machine.
Technical details
A double free vulnerability (CWE-415) exists within the Microsoft Message Queuing (MSMQ) component of Windows. The flaw is triggered when the service attempts to free the same memory location twice, leading to heap corruption. An attacker with low-privileged local access can exploit this condition to execute arbitrary code with elevated system privileges. The attack requires no user interaction but does require the attacker to have an existing account or foothold on the local system. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Message Queuing (MSMQ)
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory