Junglewise Threat Intelligence

CVE-2026-35199: Microsoft SymCrypt heap overflow in SymCryptXmssSign

CVE-2026-35199 · Severity: medium · CVSS 6.1 · Published 2026-04-06

Vendors: Microsoft.

Executive brief

SymCrypt is a core cryptographic library used by Windows for various security functions. A flaw in how it handles specific digital signature calculations could allow an attacker to cause a system crash or potentially execute unauthorized code. However, exploiting this requires the attacker to control specific signing parameters, which is unlikely in standard production environments as these operations are typically restricted to trusted hardware.

Technical details

A heap-based buffer overflow exists in SymCrypt's SymCryptXmssSign function due to an integer truncation error. The function passes a 64-bit leaf count value to a helper function that only accepts a 32-bit parameter; for XMSS^MT parameter sets with a tree height of 32 or greater, this results in the value being truncated to zero. This leads to an undersized scratch buffer allocation and a subsequent overflow during signature computation. Exploitation requires a local attacker to trigger a signing operation using an attacker-controlled parameter set, which is considered an uncommon configuration. The issue is fixed in SymCrypt version 103.11.0.

Affected products

  • Microsoft SymCrypt >= 103.5.0, < 103.11.0

Timeline

  • 2026-04-02: advisory: GitHub advisory published by Microsoft
  • 2026-04-06: disclosed: CVE-2026-35199 assigned
  • 2026-04-06: patched: Fixed in version 103.11.0

References