← back
CVE-2023-21769highCWE-125

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

43Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 89%
exploitation probability
89%top 1% of all CVEs
observed exploitation
nono source reports it
In short

Microsoft Message Queuing (MSMQ) has a vulnerability that allows an attacker to crash the service by sending specially crafted messages, preventing legitimate users from accessing the queue system. This can disrupt business operations that depend on message processing.

Technical detail

CWE-125 buffer over-read in MSMQ message processing allows remote DoS via malformed message packets without authentication. The vulnerability triggers a service crash when processing out-of-bounds memory reads, impacting availability of message queue infrastructure.

Summary generated and translated by AI from the official description.
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C