CVE-2025-21181
Published: 11 February 2025
Description
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Security Summary
CVE-2025-21181 is a Denial of Service vulnerability in Microsoft Message Queuing (MSMQ), published on 2025-02-11T18:15:29.553. It carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and is linked to CWE-400 (Uncontrolled Resource Consumption) as well as NVD-CWE-noinfo.
The vulnerability allows an unauthenticated attacker with network access to exploit MSMQ remotely with low attack complexity and no user interaction. Successful exploitation results in a high-impact denial of service, disrupting service availability without compromising confidentiality or integrity.
Microsoft's update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21181 details patching instructions. Vicarius provides a detection script at https://www.vicarius.io/vsociety/posts/cve-2025-21181-denial-of-service-vulnerability-in-microsoft-message-queuing-detection-script and a mitigation script at https://www.vicarius.io/vsociety/posts/cve-2025-21181-denial-of-service-vulnerability-in-microsoft-message-queuing-mitigation-script.
Details
- CWE(s)