Junglewise Threat Intelligence

CVE-2026-50505: Microsoft Windows Message Queuing use after free remote code execution

CVE-2026-50505 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Windows Message Queuing, a service that allows different applications to communicate across networks reliably. An authorized user could exploit this flaw to remotely run unauthorized commands or software on a target server. This could lead to a full system takeover, potentially resulting in data theft or significant operational disruption.

Technical details

This vulnerability is a use-after-free (CWE-416) located within the Windows Message Queuing (MSMQ) component. An attacker with low-level domain or local authentication can exploit this flaw by sending specially crafted messages over the network to an MSMQ server. While the attack vector is network-based, the complexity is rated as high, likely due to the specific timing or memory state required to trigger the use-after-free condition. Successful exploitation allows for remote code execution (RCE) with the privileges of the MSMQ service. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats