Junglewise Threat Intelligence

CVE-2026-70583: Microsoft Windows Core Messaging heap-based buffer overflow

CVE-2026-70583 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Core Messaging is a fundamental system component that handles inter-process communication in Windows. A heap-based buffer overflow vulnerability in this component allows an authorized local attacker to execute arbitrary code with elevated privileges, potentially compromising system security and enabling full control of the affected computer.

Technical details

A heap-based buffer overflow exists in Windows Core Messaging that can be exploited by an authorized attacker to achieve privilege escalation on the local system. The vulnerability requires the attacker to have valid credentials and local access to trigger the overflow condition. Successful exploitation results in arbitrary code execution with elevated privileges. This is a local attack vector requiring prior authentication, mitigating external remote attack scenarios but remaining critical for insider threats or compromised account scenarios.

Affected products

  • Microsoft Windows Core Messaging

Timeline

  • 2026-09-08: disclosed

References