Remote Code Execution Vulnerability in Windows Message Queuing by Microsoft
CVE-2026-83997

8.1HIGH

What is CVE-2026-83997?

The vulnerability in Windows Message Queuing stems from a use-after-free condition, enabling an unauthorized attacker to execute arbitrary code remotely via crafted messages. This can potentially compromise system integrity and lead to further exploits if not addressed promptly.

Affected Version(s)

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7725

Windows 10 Version 22H2 32-bit Systems 10.0.19045.0 < 10.0.19045.7725

Windows 11 version 23H2 ARM64-based Systems 10.0.22631.0 < 10.0.22631.7582

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.