DIRAS TAKE
Urgent: public exploit code is available, so prioritize installing the provided fixes for the listed Windows 10, Windows 11 and Server builds or otherwise restrict local access immediately.
What is CVE-2026-54992?
An attacker with local access and a low-privilege account can exploit a heap-based buffer overflow to execute code on affected Windows systems; tracked as CVE-2026-54992. Multiple Windows 10, Windows 11 and Windows Server branches are affected — see the vendor ranges and fixed builds in the advisory — and exploitation does not require user interaction. The flaw is a heap overflow in the Message Queuing Queue Manager and requires local access and low privileges to trigger. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7548 | 10.0.19044.7548 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7548 | 10.0.19045.7548 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.8875 | 10.0.26100.8875 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.8875 | 10.0.26200.8875 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2525 | 10.0.28000.2525 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23291 | 6.3.9600.23291 |
Is CVE-2026-54992 being exploited?
Public exploit code is available.
How to fix CVE-2026-54992
- Apply Microsoft updates that upgrade affected builds to the fixed builds (for example 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 6.2.9200.26226, 6.3.9600.23291).
- If you cannot patch immediately, restrict or remove local accounts that do not require interactive access and limit access to systems running Message Queuing.
- Monitor endpoints for suspicious local process creation and unusual Message Queuing behavior, and collect forensic logs for any suspected attempts.
- Follow Microsoft guidance and roll out the fixes via your normal update channels as soon as possible.
Frequently asked questions
Is CVE-2026-54992 being actively exploited?
Public exploit code is available for CVE-2026-54992.
Which Windows 10 Version 1607 versions are affected by CVE-2026-54992?
Windows 10 Version 1607 builds from 10.0.14393.0 up to before 10.0.14393.9339 are affected; fixed build is 10.0.14393.9339.
Is there a patch for CVE-2026-54992?
Yes. Microsoft published fixes; affected branches list fixed builds such as 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548 and others — apply the update matching your branch.
Does CVE-2026-54992 require authentication?
The flaw requires local access and a low-privilege account (no interactive user consent is required), so an attacker must be able to run code locally on the target.
References
- nvd.nist.gov/vuln/detail/CVE-2026-54992
- cve.org/CVERecord?id=CVE-2026-54992
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54992
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026