CVE-2026-32179
Summary
Improper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network.
Details
Improper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame.
Patches
- Fix underflow in ACK frame parsing - 1e6e999b
Impact
An attacker who successfully exploited this vulnerability could gain elevated privileges.
MSRC CVE Info
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32179
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/microsoft/msquic/security/advisories/GHSA-gvvw-8j96-8g5r, https://github.com/microsoft/msquic/commit/1e6e999b199430effeefee3d85baa0c9dd35ad5e, https://github.com/microsoft/msquic
