CVE-2026-68887
largeUnauthenticated Out-of-Bounds Read Denial of Service in Windows MSMQ Queue Manager
CVE-2026-68887 is an out-of-bounds read (CWE-125) in the Queue Manager component of Microsoft's Windows Message Queuing (MSMQ) service. A remote, unauthenticated attacker can trigger the flaw by sending network traffic that causes the Queue Manager to read beyond the intended memory buffer. The attacker gains denial of service: the CVSS vector scores availability impact as high with no confidentiality or integrity impact, meaning the affected system's messaging service can be crashed or hung. Only Windows systems where the optional MSMQ feature is installed and running are affected; it is not a default component of most modern Windows deployments. As of now there is no known exploitation, no public proof-of-concept, and the flaw is not in CISA KEV, with EPSS estimating only a ~0.8% chance of exploitation within 30 days.
What to do: Check whether the Message Queuing (MSMQ) feature is installed and running on your Windows servers (e.g., the Queue Manager service listening on MSMQ ports such as TCP 1801) and prioritize those hosts for patching when Microsoft releases updates. Until patched, restrict access to MSMQ ports to trusted internal networks and limit internet exposure of hosts running the service.
| Microsoft Windows Message Queuing (MSMQ) Queue Manager | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.