Executive brief
Windows Message Queuing is a core Windows service that manages message delivery between applications and services. A buffer over-read vulnerability in the Queue Manager component allows remote attackers to read sensitive information from system memory without authentication, potentially exposing credentials, configuration data, or other confidential information used by running applications.
Technical details
A buffer over-read vulnerability exists in the Windows Message Queuing (MSMQ) Queue Manager due to insufficient bounds checking when processing network messages. The vulnerability is remotely exploitable over a network without requiring authentication or user interaction. An unauthenticated attacker can send a specially crafted message to trigger the over-read, allowing them to disclose sensitive information from adjacent memory regions on the target system. A patch from Microsoft is expected; check the MSRC Security Update Guide for availability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed