ZeroHour

CVE-2024-49122

mass

Unauthenticated Remote Code Execution in Microsoft Message Queuing (MSMQ) on Windows

CVSS 3.1
8.1 high
EPSS
20%p97
Published
()
Modified
AI analysis

CVE-2024-49122 is a remote code execution vulnerability in Microsoft Message Queuing (MSMQ), a legacy optional Windows messaging component, caused by a use-after-free condition (CWE-416) reached through a race condition (CWE-362). A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network traffic to a host with the MSMQ feature enabled; the high attack complexity (CVSS 8.1, AC:H) reflects timing-sensitive race-condition exploitation, with no privileges or user interaction required. Successful exploitation yields code execution on the target host with high impact on confidentiality, integrity, and availability, and can serve as a foothold for lateral movement. Affected organizations are those running the listed Windows 10/11 client or Windows Server versions with the MSMQ feature installed and running. As of the December 2024 disclosure there is no known public PoC, the flaw is not yet in CISA KEV, but the EPSS score of 20.4% (97th percentile) indicates an elevated likelihood of exploitation within 30 days.

What to do: Apply the December 2024 Patch Tuesday security updates for the affected Windows 10, Windows 11, and Windows Server versions. Audit hosts for the MSMQ feature (e.g., check installed optional features and whether TCP port 1801 is listening) and disable or remove MSMQ where it is not required; prioritize patching internet-exposed or legacy Windows Server systems, and note that Windows Server 2008/2012 devices may require extended-security-update channels.

Affected
microsoft windows 101507, 1607, 1809, 21H2, 22H2
microsoft windows 1122H2, 23H2, 24H2
microsoft windows server2008, 2012, 2016, 2019
Estimated exposure
masslikely 1M+ Windows systems with MSMQ enabled (from an install base of hundreds of millions of Windows 10/11 and Server endpoints), though far fewer are… — The affected versions span the entire mainstream Windows client and server line, whose combined install base is well over a billion devices, so even the small, unknown fraction with the optional MSMQ feature enabled plausibly exceeds one…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-416, CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news