CVE-2025-21285
massNULL Pointer Dereference DoS in Microsoft Message Queuing (MSMQ)
CVE-2025-21285 is a denial-of-service vulnerability in Microsoft Message Queuing (MSMQ), caused by a NULL pointer dereference (CWE-476) in the MSMQ service. An unauthenticated remote attacker can trigger the crash by sending specially crafted network traffic to a host running MSMQ — the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms network exploitation with no privileges or user interaction required. The impact is availability-only (C:N/I:N/A:H): the attacker can disrupt the MSMQ service and any applications that depend on message queuing, but cannot execute code or read or modify data. Affected systems are the listed Windows 10, Windows 11, and Windows Server releases, but only where the optional MSMQ feature is installed and enabled. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, but the EPSS score of 55.7% (99th percentile) indicates an elevated likelihood of exploitation within the next 30 days.
What to do: Apply Microsoft's current cumulative (Patch Tuesday) security updates for each affected Windows release on any host with MSMQ installed, prioritizing internet-reachable or multi-user servers given the 99th-percentile EPSS score. Determine exposure by checking whether the MSMQ feature is enabled (e.g., via Windows Features on clients or Get-WindowsFeature MSMQ on Server); where MSMQ is not required, remove the feature. If MSMQ must remain, restrict untrusted network access to the MSMQ service (default messaging port TCP/UDP 1801) with host or perimeter firewall rules until patched.
| microsoft Windows 10 | 1507 (all builds prior to Microsoft's fix) |
| microsoft Windows 10 | 1607 (all builds prior to Microsoft's fix) |
| microsoft Windows 10 | 1809 (all builds prior to Microsoft's fix) |
| microsoft Windows 10 | 21H2 (all builds prior to Microsoft's fix) |
| microsoft Windows 10 | 22H2 (all builds prior to Microsoft's fix) |
| microsoft Windows 11 | 22H2 (all builds prior to Microsoft's fix) |
| microsoft Windows 11 | 23H2 (all builds prior to Microsoft's fix) |
| microsoft Windows 11 | 24H2 (all builds prior to Microsoft's fix) |
| microsoft Windows Server 2008 | 2008 (all builds prior to Microsoft's fix) |
| microsoft Windows Server 2012 | 2012 (all builds prior to Microsoft's fix) |
| microsoft Windows Server 2016 | 2016 (all builds prior to Microsoft's fix) |
| microsoft Windows Server 2019 | 2019 (all builds prior to Microsoft's fix) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.