CVE-2025-21277
Published: 14 January 2025
Description
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Security Summary
CVE-2025-21277 is a Denial of Service vulnerability in Microsoft Message Queuing (MSMQ). It has a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and is associated with CWE-126 and NVD-CWE-noinfo. The vulnerability was published on 2025-01-14.
An unauthenticated attacker can exploit this vulnerability over the network with low complexity and no user interaction required. Successful exploitation results in a high impact on availability, enabling denial of service against affected MSMQ instances.
The Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21277 provides details on mitigation and patches.
Details
- CWE(s)