CVE-2025-21289
Published: 14 January 2025
Description
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Security Summary
CVE-2025-21289 is a Denial of Service vulnerability in Microsoft Message Queuing (MSMQ). Published on 2025-01-14T18:15:50.363, it is associated with CWE-400 (Uncontrolled Resource Consumption) and has a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating high availability impact with no impact on confidentiality or integrity.
The vulnerability can be exploited by an unauthenticated attacker over the network with low attack complexity and no user interaction required. Successful exploitation results in a denial of service condition, disrupting MSMQ service availability.
Microsoft's update guide provides details on mitigation, available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21289.
Details
- CWE(s)