Junglewise Threat Intelligence

CVE-2026-34329: Microsoft Windows Message Queuing heap overflow

CVE-2026-34329 · Severity: high · CVSS 8.8 · Published 2026-05-12

Executive brief

A security vulnerability exists in Windows Message Queuing, a service used by applications to communicate reliably across networks. An attacker located on the same local network could exploit this flaw to take full control of an affected system without needing any login credentials. This could lead to the theft of sensitive data, disruption of business operations, or the installation of malicious software.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Microsoft Windows Message Queuing (MSMQ) service. The vulnerability is triggered when the service improperly handles specially crafted network packets, leading to memory corruption. An unauthenticated attacker located on the same subnet or local network (Adjacent vector) can exploit this to achieve remote code execution with high privileges. No user interaction is required for successful exploitation. Microsoft has released security updates to address this issue via the MSRC update guide.

Affected products

  • Microsoft Windows Message Queuing (MSMQ)

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft published the security update guide.

References

Related threats