• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-54992: local code execution in Microsoft Windows 10 Version 1607

An attacker with local access and a low-privilege account can exploit a heap-based buffer overflow to execute code on affected Windows systems; tracked as CVE-2026-54992. Multiple Windows 10, Windows 11 and Windows Server branches are affected — see the vendor ranges and fixed builds in the advisory — and exploitation does not require user interaction. The flaw is a heap overflow in the Message Queuing Queue Manager and requires local access and low privileges to trigger.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00337
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code is available, so prioritize installing the provided fixes for the listed Windows 10, Windows 11 and Server builds or otherwise restrict local access immediately.

What is CVE-2026-54992?

An attacker with local access and a low-privilege account can exploit a heap-based buffer overflow to execute code on affected Windows systems; tracked as CVE-2026-54992. Multiple Windows 10, Windows 11 and Windows Server branches are affected — see the vendor ranges and fixed builds in the advisory — and exploitation does not require user interaction. The flaw is a heap overflow in the Message Queuing Queue Manager and requires local access and low privileges to trigger. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.754810.0.19044.7548
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.754810.0.19045.7548
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.887510.0.26100.8875
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.887510.0.26200.8875
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.252510.0.28000.2525
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.232916.3.9600.23291

Is CVE-2026-54992 being exploited?

Public exploit code is available.

How to fix CVE-2026-54992

  1. Apply Microsoft updates that upgrade affected builds to the fixed builds (for example 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 6.2.9200.26226, 6.3.9600.23291).
  2. If you cannot patch immediately, restrict or remove local accounts that do not require interactive access and limit access to systems running Message Queuing.
  3. Monitor endpoints for suspicious local process creation and unusual Message Queuing behavior, and collect forensic logs for any suspected attempts.
  4. Follow Microsoft guidance and roll out the fixes via your normal update channels as soon as possible.

Frequently asked questions

Is CVE-2026-54992 being actively exploited?

Public exploit code is available for CVE-2026-54992.

Which Windows 10 Version 1607 versions are affected by CVE-2026-54992?

Windows 10 Version 1607 builds from 10.0.14393.0 up to before 10.0.14393.9339 are affected; fixed build is 10.0.14393.9339.

Is there a patch for CVE-2026-54992?

Yes. Microsoft published fixes; affected branches list fixed builds such as 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548 and others — apply the update matching your branch.

Does CVE-2026-54992 require authentication?

The flaw requires local access and a low-privilege account (no interactive user consent is required), so an attacker must be able to run code locally on the target.

References