CVE-2026-54992 is a high-severity heap-based buffer overflow in the Windows Message Queuing Queue Manager. Improper handling of data in the Queue Manager can corrupt heap memory and permit an unauthorized local attacker to execute code on an affected Windows system. Microsoft classifies the vulnerability as remote code execution, but the attack vector is local and the flaw is not remotely exploitable.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real proof-of-concept exploit for CVE-2026-54992 targeting Microsoft MSMQ on Windows. It is not a framework module; it is a standalone lab PoC demonstrating denial of service only. The repository contains two main binaries: a fake MS-MQRR RPC server (`fake_remote_read_server.c`) and a trigger client (`remote_read_trigger.c`). The helper server emulates the MSMQ RemoteRead interface over RPC (`ncacn_ip_tcp`) on TCP 2105 and returns crafted `SectionBuffer` values designed to trigger a 32-bit integer overflow in the target's `mqqm.dll` packet allocation logic. The trigger client uses normal MSMQ APIs (`MQOpenQueue`, `MQReceiveMessage`) to make the vulnerable target's local MSMQ service request a remote read from the helper-hosted queue, causing `mqsvc.exe` to crash. Repository structure: autogenerated RPC interface files (`fake_remote_read.idl`, `fake_remote_read.h`, `fake_remote_read_s.c`, `fake_remote_read_i.c`) define and implement the RemoteRead RPC surface; `fake_remote_read_server.c` is the core exploit logic and listener; `remote_read_trigger.c` is the client-side trigger; `legitimate_packet_template.h` embeds a packet template used to shape returned data; PowerShell scripts automate setup and cleanup (`setup-target.ps1`, `start-emulator.ps1`, `invoke-crash.ps1`, `restore-helper.ps1`); `Makefile` builds both Windows executables with MinGW-w64. Exploit capability: the server returns malicious section allocation sizes such as `0x2000` and `0xffffe010`, which sum to `0x100000010` and wrap to `0x10` in 32-bit arithmetic. The target allocates based on the wrapped size but later processes original lengths, leading to out-of-bounds write and service termination. The code includes tunable parameters (`--controlled`, `--wrap`, and neighbor-related options visible in the server) for shaping heap layout and packet contents, but the documented outcome remains a crash/DoS rather than RCE. The PowerShell scripts also configure WER crash dumps and firewall rules, stop MSMQ on the helper, verify TCP 2105 binding, and validate whether the target service stopped with exit code 1067 after exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Microsoft-patched vulnerability mentioned only in the Sophos protections table without further detail.
A heap-based buffer overflow in Windows Message Queuing Queue Manager that allows local code execution by an unauthorized attacker. It is significant due to its high CVSS 3.1 score of 8.4 and broad impact across multiple Windows client and server versions.
A heap-based buffer overflow remote code execution vulnerability in Microsoft Message Queuing Queue Manager.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.