Junglewise Threat Intelligence

CVE-2026-68887: Microsoft Windows Message Queuing out-of-bounds read

CVE-2026-68887 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows Message Queuing is a service that enables distributed messaging across corporate networks. An out-of-bounds read vulnerability allows a remote attacker to cause the Message Queuing service to crash, disrupting messaging operations and potentially affecting dependent business processes without requiring authentication.

Technical details

This vulnerability is an out-of-bounds read in the Windows Message Queuing Queue Manager component. The vulnerability can be triggered over the network by an unauthenticated attacker, leading to a denial of service condition where the service crashes or becomes unresponsive. The out-of-bounds read occurs when the Queue Manager processes specially crafted network requests, allowing an attacker to access memory beyond the intended buffer boundaries. This results in service termination without requiring any authentication or user interaction.

Affected products

  • Microsoft Windows Message Queuing <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats