CVE-2026-72932
largeBuffer Over-Read Information Disclosure in Windows Message Queuing
CVE-2026-72932 is a buffer over-read (CWE-126) in the Queue Manager component of Windows Message Queuing (MSMQ), Microsoft's legacy message-queuing service shipped as an optional Windows feature. An unauthenticated remote attacker can trigger the flaw over the network, for example by sending crafted network input to the MSMQ service, causing the Queue Manager to read past the end of an allocated buffer. Successful exploitation discloses sensitive memory contents, so the impact is confidentiality only; the CVSS vector shows no integrity or availability impact, and no privileges or user interaction are required. Any Windows system with the optional Message Queuing feature installed and reachable over the network is potentially affected, with enterprise application and integration servers the most likely deployments. As of this analysis there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a roughly 1% probability of exploitation within 30 days.
What to do: Apply the Microsoft security update for CVE-2026-72932 through Windows Update as soon as it is available for your Windows editions, prioritizing servers where MSMQ is enabled and network-reachable. As an interim mitigation, disable the Message Queuing optional feature on systems that do not use it, or restrict network access to MSMQ endpoints (e.g., TCP/UDP port 1801 and related MSMQ ports). Audit your estate for systems with the MSMQ feature installed and give priority to any that are exposed to untrusted networks.
| Microsoft Windows Message Queuing (MSMQ) - Queue Manager | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
- Weakness
- CWE-126
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.