ZeroHour

CVE-2025-21285

mass

NULL Pointer Dereference DoS in Microsoft Message Queuing (MSMQ)

CVSS 3.1
7.5 high
EPSS
56%p99
Published
()
Modified
AI analysis

CVE-2025-21285 is a denial-of-service vulnerability in Microsoft Message Queuing (MSMQ), caused by a NULL pointer dereference (CWE-476) in the MSMQ service. An unauthenticated remote attacker can trigger the crash by sending specially crafted network traffic to a host running MSMQ — the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms network exploitation with no privileges or user interaction required. The impact is availability-only (C:N/I:N/A:H): the attacker can disrupt the MSMQ service and any applications that depend on message queuing, but cannot execute code or read or modify data. Affected systems are the listed Windows 10, Windows 11, and Windows Server releases, but only where the optional MSMQ feature is installed and enabled. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, but the EPSS score of 55.7% (99th percentile) indicates an elevated likelihood of exploitation within the next 30 days.

What to do: Apply Microsoft's current cumulative (Patch Tuesday) security updates for each affected Windows release on any host with MSMQ installed, prioritizing internet-reachable or multi-user servers given the 99th-percentile EPSS score. Determine exposure by checking whether the MSMQ feature is enabled (e.g., via Windows Features on clients or Get-WindowsFeature MSMQ on Server); where MSMQ is not required, remove the feature. If MSMQ must remain, restrict untrusted network access to the MSMQ service (default messaging port TCP/UDP 1801) with host or perimeter firewall rules until patched.

Affected
microsoft Windows 101507 (all builds prior to Microsoft's fix)
microsoft Windows 101607 (all builds prior to Microsoft's fix)
microsoft Windows 101809 (all builds prior to Microsoft's fix)
microsoft Windows 1021H2 (all builds prior to Microsoft's fix)
microsoft Windows 1022H2 (all builds prior to Microsoft's fix)
microsoft Windows 1122H2 (all builds prior to Microsoft's fix)
microsoft Windows 1123H2 (all builds prior to Microsoft's fix)
microsoft Windows 1124H2 (all builds prior to Microsoft's fix)
microsoft Windows Server 20082008 (all builds prior to Microsoft's fix)
microsoft Windows Server 20122012 (all builds prior to Microsoft's fix)
microsoft Windows Server 20162016 (all builds prior to Microsoft's fix)
microsoft Windows Server 20192019 (all builds prior to Microsoft's fix)
Estimated exposure
mass>1M systems (hundreds of millions of Windows devices fall within the affected version range; only the MSMQ-enabled subset is actually vulnerable) — The listed releases span essentially the entire Windows installed base (hundreds of millions of devices and servers), but MSMQ is an optional enterprise feature rather than a default component, so the realistically vulnerable population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.