GHSA-92f5-vc22-8j33CriticalCVSS 9.8

Microsoft QUIC: Remote Code Execution Vulnerability

Published
September 8, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

Details

New network path creations and removals triggered by incoming packets can lead to a pointer invalidation.

Patches

Impact

An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.

🎯 Affected products4

  • nuget/Microsoft.Native.Quic.MsQuic.OpenSSL:>= 2.5.3, < 2.5.10
  • nuget/Microsoft.Native.Quic.MsQuic.Schannel:>= 2.5.3, < 2.5.10
  • nuget/Microsoft.Native.Quic.MsQuic.OpenSSL:< 2.4.19
  • nuget/Microsoft.Native.Quic.MsQuic.Schannel:< 2.4.19

🔗 References (12)