You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
MsQuic has a Remote Elevation of Privilege Vulnerability
Critical severity
GitHub Reviewed
Published
Apr 15, 2026
in
microsoft/msquic
•
Updated Apr 16, 2026
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Learn more on MITRE.
Summary
Improper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network.
Details
Improper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame.
Patches
Impact
An attacker who successfully exploited this vulnerability could gain elevated privileges.
MSRC CVE Info
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32179
References