Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-62719

CVE-2026-62719: Windows 10 1607 Privilege Escalation Flaw

CVE-2026-62719 is a privilege escalation vulnerability in Windows 10 1607 affecting Windows Message Queuing. An authorized attacker can exploit a heap-based buffer overflow to gain elevated privileges locally.

Published:

CVE-2026-62719 Overview

CVE-2026-62719 is a heap-based buffer overflow vulnerability [CWE-122] in the Microsoft Windows Message Queuing (MSMQ) service. An authorized local attacker can exploit the flaw to elevate privileges on the affected host. The vulnerability affects a broad range of supported Windows client and server versions, from Windows 10 1607 through Windows 11 26H1, and from Windows Server 2012 through Windows Server 2025. Microsoft published the advisory on 2026-08-11, and the entry was last modified on 2026-08-13.

Critical Impact

Successful exploitation grants elevated privileges on the local system, enabling full compromise of confidentiality, integrity, and availability on any host running the Message Queuing service.

Affected Products

  • Microsoft Windows 10 (1607, 1809, 21H2, 22H2) on x86, x64, and ARM64
  • Microsoft Windows 11 (23H2, 24H2, 25H2, 26H1) on x64 and ARM64
  • Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025

Discovery Timeline

  • 2026-08-11 - CVE-2026-62719 published to NVD
  • 2026-08-13 - Last updated in NVD database

Technical Details for CVE-2026-62719

Vulnerability Analysis

The vulnerability resides in the Windows Message Queuing (MSMQ) service, which processes queued messages between applications and hosts. A heap-based buffer overflow [CWE-122] occurs when the service handles attacker-controlled input without adequately validating buffer boundaries against allocated heap memory.

An authorized attacker with local access can trigger the overflow through crafted interactions with the MSMQ service. Because MSMQ typically runs with elevated privileges, corrupting heap metadata or adjacent objects can allow the attacker to overwrite function pointers or control structures. Exploitation results in code execution in the context of the privileged MSMQ process, effectively elevating the attacker from a standard user to a higher privilege tier.

The attack requires local access and low-privileged authentication, but no user interaction. The EPSS probability is 0.318% with a percentile of 24.45, reflecting a relatively low predicted exploitation likelihood at the time of publication.

Root Cause

The root cause is improper bounds checking during heap allocation and copy operations inside the MSMQ message-handling code path. When the service parses message payloads or associated metadata, an oversized or malformed field causes a write past the end of a heap buffer, corrupting adjacent heap chunks.

Attack Vector

Exploitation requires local access and valid credentials on the target system. The attacker sends specially crafted requests to the local MSMQ service to trigger the overflow. No user interaction is needed, and the scope remains unchanged, meaning impact is confined to the vulnerable component's security authority. Refer to the Microsoft Vulnerability Advisory CVE-2026-62719 for authoritative technical details.

No public proof-of-concept exploit code has been published, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2026-62719

Indicators of Compromise

  • Unexpected crashes, restarts, or access violations in the mqsvc.exe process or associated MSMQ modules.
  • Creation of new privileged processes spawned as children of mqsvc.exe following local user activity.
  • Anomalous local interactions with MSMQ endpoints from standard user accounts that do not typically use Message Queuing.

Detection Strategies

  • Monitor Windows Error Reporting and application crash telemetry for faults involving mqsvc.exe and MSMQ dependencies.
  • Alert on process lineage anomalies where mqsvc.exe spawns command interpreters such as cmd.exe, powershell.exe, or other LOLBins.
  • Baseline expected local MSMQ usage per host and flag deviations from standard, non-privileged accounts.

Monitoring Recommendations

  • Enable audit logging for local service interactions and process creation events (Event ID 4688) with command-line capture.
  • Ingest endpoint telemetry into a centralized analytics platform to correlate MSMQ crashes with subsequent privilege changes.
  • Track whether the Message Queuing feature is installed and enabled on hosts that do not require it, and prioritize monitoring on hosts where it is active.

How to Mitigate CVE-2026-62719

Immediate Actions Required

  • Apply the Microsoft security update for CVE-2026-62719 across all affected Windows client and server versions.
  • Inventory hosts running the Message Queuing (MSMQ) feature and prioritize patching on servers exposing MSMQ functionality.
  • Restrict interactive and remote logon rights on hosts where MSMQ is required, limiting the pool of users who could achieve local access.

Patch Information

Microsoft has released fixes through the standard security update channel. Consult the Microsoft Vulnerability Advisory CVE-2026-62719 for the specific KB articles and cumulative updates that correspond to each affected Windows version.

Workarounds

  • Disable the Windows Message Queuing feature on systems that do not require it, using the Server Manager or the Disable-WindowsOptionalFeature PowerShell cmdlet.
  • Enforce least privilege on local accounts so that standard users cannot install software or interact with sensitive services.
  • Block inbound TCP port 1801 and related MSMQ ports at the host firewall where external message queuing is not required.
bash
# Configuration example: disable MSMQ feature if not required
Disable-WindowsOptionalFeature -Online -FeatureName MSMQ-Server -NoRestart

# Verify Message Queuing service state
Get-Service -Name MSMQ

# Block MSMQ TCP port at the host firewall
New-NetFirewallRule -DisplayName "Block MSMQ 1801" -Direction Inbound -Protocol TCP -LocalPort 1801 -Action Block

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.