CVE-2025-21277
largeUnauthenticated Remote DoS via Buffer Over-read in Microsoft Message Queuing
Microsoft Message Queuing (MSMQ) — the optional Windows messaging component used by enterprise and legacy applications — contains a buffer over-read (CWE-126) that an unauthenticated remote attacker can trigger by sending specially crafted messages to the MSMQ service, which listens on the network (typically TCP 1801) on systems where the feature is enabled. Successful exploitation carries a high availability impact only: the queuing service can crash or stop responding, disrupting applications that depend on it, with no confidentiality or integrity impact per the CVSS vector. Any affected Windows 10, Windows 11, or Windows Server release with the MSMQ feature installed is exposed, although the component is not enabled by default on most systems. Exploitation has not yet been observed in the wild, no public proof-of-concept is known, and the flaw is not in CISA's KEV; however, its EPSS of 38.6% (98th percentile) indicates a comparatively high likelihood of exploitation within the next 30 days.
What to do: Apply Microsoft's security update for MSMQ on all affected Windows 10/11 and Windows Server builds, prioritizing servers with MSMQ reachable from untrusted networks. Until patched, restrict network access to the MSMQ service (TCP 1801 and associated MSMQ ports) to trusted hosts, or disable the optional MSMQ feature where it is not required — check installation state with 'Get-WindowsFeature MSMQ' on Server or 'optionalfeatures.exe' on clients. No public PoC or in-the-wild exploitation is known yet, but the elevated EPSS warrants prompt patching.
| Microsoft Windows 10 | 1507 |
| Microsoft Windows 10 | 1607 |
| Microsoft Windows 10 | 1809 |
| Microsoft Windows 10 | 21H2 |
| Microsoft Windows 10 | 22H2 |
| Microsoft Windows 11 | 22H2 |
| Microsoft Windows 11 | 23H2 |
| Microsoft Windows 11 | 24H2 |
| Microsoft Windows Server 2008 | 2008 |
| Microsoft Windows Server 2012 | 2012 |
| Microsoft Windows Server 2016 | 2016 |
| Microsoft Windows Server 2019 | 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-126
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.