Microsoft disclosed two new vulnerabilities in Windows Message Queuing (MSMQ): CVE-2026-34329, a heap-based buffer overflow that can let an unauthorized attacker on an adjacent network send a specially crafted MSMQ message and achieve remote code execution, and CVE-2026-33838, a double-free flaw that can allow a local low-privileged attacker to gain SYSTEM privileges. Microsoft rated both issues Important, assigned CVSS scores of 8.8 and 7.8 respectively, said neither was publicly disclosed or exploited in the wild at publication, and released fixes for both vulnerabilities. Microsoft credited Azure Yang (@4zure9) of Kunlun Lab with reporting CVE-2026-34329.
The disclosures add to a longer pattern of serious MSMQ security issues previously tracked by Microsoft, including CVE-2023-21554 and multiple 2023 MSMQ remote code execution bugs such as CVE-2023-36572, CVE-2023-36575, CVE-2023-36578, CVE-2023-36583, CVE-2023-36589, and CVE-2023-36590. The repeated appearance of MSMQ flaws across releases underscores the continued risk posed by the legacy Windows messaging component, particularly where the service is enabled and reachable from adjacent networks or accessible to local users.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed CVE-2026-34329, an Important MSMQ remote code execution vulnerability caused by a heap-based buffer overflow and rated CVSS 8.8. Microsoft said the bug was not publicly disclosed or exploited in the wild at publication, released a fix, and credited Azure Yang of Kunlun Lab for reporting it.
Microsoft disclosed CVE-2026-33838, an Important Windows Message Queuing elevation-of-privilege vulnerability caused by a double-free weakness. The company said local attackers with low privileges could potentially gain SYSTEM privileges, and that a fix was available at publication.
Microsoft published Security Update Guide entries for several MSMQ remote code execution vulnerabilities, including CVE-2023-36572, CVE-2023-36575, CVE-2023-36578, CVE-2023-36583, CVE-2023-36589, and CVE-2023-36590. These entries show a coordinated October 2023 disclosure and patch release affecting MSMQ.
Microsoft published a Security Update Guide entry for CVE-2023-21554, identifying a remote code execution vulnerability in Microsoft Message Queuing (MSMQ). The disclosure indicates a security update was issued as part of Microsoft's April 2023 release cycle.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.