CVE-2025-21290
Published: 14 January 2025
Description
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Security Summary
CVE-2025-21290 is a Denial of Service vulnerability in Microsoft Message Queuing (MSMQ). Published on 2025-01-14, it is associated with CWE-400 (Uncontrolled Resource Consumption) and has a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating high severity due to its potential for significant availability disruption.
An unauthenticated attacker can exploit this vulnerability remotely over the network with low attack complexity and without requiring user interaction. Successful exploitation results in high-impact denial of service, potentially rendering the affected MSMQ service unavailable.
The Microsoft Security Response Center advisory provides details on mitigation and patches at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21290.
Details
- CWE(s)