{"id":"GHSA-gvvw-8j96-8g5r","summary":"MsQuic has a Remote Elevation of Privilege Vulnerability","details":"### Summary\nImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network.\n\n### Details\n Improper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame.\n\n#### Patches\n- Fix underflow in ACK frame parsing - 1e6e999b\n\n### Impact\nAn attacker who successfully exploited this vulnerability could gain elevated privileges.","aliases":["CVE-2026-32179"],"modified":"2026-05-08T15:32:31.863480Z","published":"2026-04-16T01:04:03Z","database_specific":{"github_reviewed_at":"2026-04-16T01:04:03Z","nvd_published_at":null,"cwe_ids":["CWE-191"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/microsoft/msquic/security/advisories/GHSA-gvvw-8j96-8g5r"},{"type":"WEB","url":"https://github.com/microsoft/msquic/commit/1e6e999b199430effeefee3d85baa0c9dd35ad5e"},{"type":"PACKAGE","url":"https://github.com/microsoft/msquic"}],"affected":[{"package":{"name":"Microsoft.Native.Quic.MsQuic.OpenSSL","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.Native.Quic.MsQuic.OpenSSL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0-ci.532574"},{"fixed":"2.5.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-gvvw-8j96-8g5r/GHSA-gvvw-8j96-8g5r.json"}},{"package":{"name":"Microsoft.Native.Quic.MsQuic.Schannel","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.Native.Quic.MsQuic.Schannel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0-ci.532574"},{"fixed":"2.5.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-gvvw-8j96-8g5r/GHSA-gvvw-8j96-8g5r.json"}},{"package":{"name":"Microsoft.Native.Quic.MsQuic.Schannel","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.Native.Quic.MsQuic.Schannel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18"}]}],"versions":["1.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-gvvw-8j96-8g5r/GHSA-gvvw-8j96-8g5r.json"}},{"package":{"name":"Microsoft.Native.Quic.MsQuic.OpenSSL","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.Native.Quic.MsQuic.OpenSSL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18"}]}],"versions":["1.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-gvvw-8j96-8g5r/GHSA-gvvw-8j96-8g5r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}