CVE-2024-49122
massUnauthenticated Remote Code Execution in Microsoft Message Queuing (MSMQ) on Windows
CVE-2024-49122 is a remote code execution vulnerability in Microsoft Message Queuing (MSMQ), a legacy optional Windows messaging component, caused by a use-after-free condition (CWE-416) reached through a race condition (CWE-362). A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network traffic to a host with the MSMQ feature enabled; the high attack complexity (CVSS 8.1, AC:H) reflects timing-sensitive race-condition exploitation, with no privileges or user interaction required. Successful exploitation yields code execution on the target host with high impact on confidentiality, integrity, and availability, and can serve as a foothold for lateral movement. Affected organizations are those running the listed Windows 10/11 client or Windows Server versions with the MSMQ feature installed and running. As of the December 2024 disclosure there is no known public PoC, the flaw is not yet in CISA KEV, but the EPSS score of 20.4% (97th percentile) indicates an elevated likelihood of exploitation within 30 days.
What to do: Apply the December 2024 Patch Tuesday security updates for the affected Windows 10, Windows 11, and Windows Server versions. Audit hosts for the MSMQ feature (e.g., check installed optional features and whether TCP port 1801 is listening) and disable or remove MSMQ where it is not required; prioritize patching internet-exposed or legacy Windows Server systems, and note that Windows Server 2008/2012 devices may require extended-security-update channels.
| microsoft windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| microsoft windows 11 | 22H2, 23H2, 24H2 |
| microsoft windows server | 2008, 2012, 2016, 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-416, CWE-362
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H