{"id":"CVE-2026-32179","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-32179","summary":"MsQuic has a Remote Elevation of Privilege Vulnerability","details":"### Summary\nImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network.\n\n### Details\n Improper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame.\n\n#### Patches\n- Fix underflow in ACK frame parsing - 1e6e999b\n\n### Impact\nAn attacker who successfully exploited this vulnerability could gain elevated privileges.","published":"2026-04-16T01:04:03Z","modified":"2026-05-08T15:32:31.863480Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"NuGet","name":"Microsoft.Native.Quic.MsQuic.OpenSSL","fixedVersion":"2.5.7"},{"ecosystem":"NuGet","name":"Microsoft.Native.Quic.MsQuic.Schannel","fixedVersion":"2.5.7"},{"ecosystem":"NuGet","name":"Microsoft.Native.Quic.MsQuic.Schannel","fixedVersion":"2.4.18"},{"ecosystem":"NuGet","name":"Microsoft.Native.Quic.MsQuic.OpenSSL","fixedVersion":"2.4.18"}],"fix":{"url":"https://github.com/microsoft/msquic/commit/1e6e999b199430effeefee3d85baa0c9dd35ad5e","label":"microsoft/msquic@1e6e999"},"references":[{"type":"WEB","url":"https://github.com/microsoft/msquic/security/advisories/GHSA-gvvw-8j96-8g5r"},{"type":"WEB","url":"https://github.com/microsoft/msquic/commit/1e6e999b199430effeefee3d85baa0c9dd35ad5e"},{"type":"PACKAGE","url":"https://github.com/microsoft/msquic"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-08T15:32:31.863480Z"}}