Junglewise Threat Intelligence

CVE-2026-69645: Microsoft Windows Message Queuing use-after-free privilege escalation

CVE-2026-69645 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Message Queuing is a Microsoft component that allows applications to exchange messages asynchronously. A use-after-free vulnerability in this component allows an authorized local attacker to execute arbitrary code with elevated privileges, potentially compromising the entire system or gaining access to sensitive data.

Technical details

This vulnerability is a use-after-free memory flaw in Windows Message Queuing that permits an authorized local attacker to elevate privileges. The attack requires local access and existing user credentials, but does not require network connectivity. An attacker exploiting this vulnerability can achieve arbitrary code execution with system-level privileges. A security update is available from Microsoft to remediate this issue.

Affected products

  • Microsoft Windows Message Queuing

Timeline

  • 2026-09-08: disclosed

References

Related threats