Junglewise Threat Intelligence

CVE-2026-69579: Microsoft Windows Message Queuing use after free remote code execution

CVE-2026-69579 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

Windows Message Queuing is a Microsoft service that allows applications to reliably exchange messages across networks. A use-after-free vulnerability in this service could allow an unauthorized attacker to execute arbitrary code remotely on affected systems, potentially leading to complete system compromise and lateral movement within a network.

Technical details

A use-after-free vulnerability exists in Windows Message Queuing, a system service component responsible for message delivery and queuing functionality. The vulnerability allows an unauthenticated attacker to trigger a memory safety flaw by sending specially crafted network packets to the Message Queuing service. This results in remote code execution with system privileges, requiring only network connectivity to the affected machine. No authentication or user interaction is required to exploit this issue. A patch has been released by Microsoft to address this vulnerability.

Affected products

  • Microsoft Windows Message Queuing

Timeline

  • 2026-09-08: disclosed

References

Related threats