Junglewise Threat Intelligence

CVE-2026-54992: Microsoft Windows Message Queuing heap overflow in Queue Manager

CVE-2026-54992 · Severity: high · CVSS 8.4 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Message Queuing (MSMQ) service, which is used by applications to communicate across different networks and systems. An attacker who already has basic access to a computer could exploit this flaw to run malicious software with high-level system privileges. This could lead to a full takeover of the affected machine, allowing the attacker to steal data or disrupt business operations.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists within the Windows Message Queuing (MSMQ) Queue Manager. The flaw is triggered when the component incorrectly handles specially crafted data, leading to memory corruption. Although the attack vector is local, the vulnerability does not require prior administrative privileges or user interaction to exploit. Successful exploitation allows an attacker to execute arbitrary code with elevated privileges on the local system. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard and Server Core

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats