ZeroHour

CVE-2026-69645

mass

Use-After-Free Local Privilege Escalation in Windows Message Queuing (MSMQ)

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69645 is a use-after-free memory-corruption flaw (CWE-416) in the Windows Message Queuing (MSMQ) component of Microsoft Windows. A local attacker who is already authenticated to the machine with low privileges can trigger the flaw by interacting with the Message Queuing service in a way that causes it to reuse freed memory; the high attack complexity (AC:H) means reliable exploitation requires favorable conditions, though no user interaction is required. Successful exploitation elevates the attacker's privileges on the local system, with high impact on confidentiality, integrity, and availability, making this a post-compromise privilege-escalation issue rather than a remote or network-facing flaw. Any Windows installation with the optional Message Queuing feature installed and running is affected; systems without the MSMQ service are not exposed. As of this analysis there is no evidence of exploitation in the wild, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69645 when it is released, prioritizing enterprise servers and workstations that run the Message Queuing service (inventory via the MSMQ service entry or the Windows optional-features list). Where MSMQ is not required, disabling or removing the optional feature removes the attack surface. Because exploitation requires an existing low-privilege local foothold and no PoC or in-the-wild use is known, a standard Patch Tuesday cadence is reasonable unless the affected host is high-value or widely shared.

Affected
Microsoft Windows Message Queuing (MSMQ) component of Microsoft Windows
Estimated exposure
massPlausibly on the order of 1-10 million Windows installations with the MSMQ feature enabled (estimate, not a measured count) — Windows runs on well over a billion devices and MSMQ is an OS-bundled optional feature that is not enabled by default but is commonly retained in enterprise, server, and line-of-business deployments, so even a small minority of the Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.