← Vulnerability feed

Vulnerability record · CVE-2007-3039 · published 12 December 2007

CVE-2007-3039: Microsoft MSMQ RPC Stack Buffer Overflow Enables Remote Code Execution

Microsoft · Message Queuing

The Microsoft Message Queuing (MSMQ) service contains a stack-based buffer overflow triggered by a long string in an opnum 0x06 RPC call to port 2103. A remote attacker who can reach that RPC interface can corrupt memory and execute arbitrary code in the service context. The flaw affects Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2, and is noted as remotely exploitable on Windows 2000 Server.

9.0 CVSS 2.0 High EPSS 69% · top 0.7% CWE-119 · Memory buffer overflow
9.0CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe flaw is a remotely reachable, pre-authentication-adjacent memory corruption with public exploit code and very high EPSS, but it is limited to legacy Windows 2000 and XP SP2 systems that are largely out of support.

What it is

The Microsoft Message Queuing (MSMQ) service contains a stack-based buffer overflow triggered by a long string in an opnum 0x06 RPC call to port 2103. A remote attacker who can reach that RPC interface can corrupt memory and execute arbitrary code in the service context. The flaw affects Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2, and is noted as remotely exploitable on Windows 2000 Server.

Impact

Successful exploitation gives the attacker arbitrary code execution with the privileges of the MSMQ service, which on Windows 2000 Server can mean full control of the host. That allows data theft, service disruption, or use of the machine as a foothold for further network activity.

Attack surface

The vulnerability is reached over the network through an RPC call to port 2103 using opnum 0x06. The CVSS vector indicates authentication is required (Au:S), and no user interaction is described.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.69055 (99.3rd percentile), and multiple public Exploit-DB entries exist, indicating mature public exploit code. No ransomware association is documented.

What to do

  • Apply Microsoft security bulletin MS07-065 to affected Windows 2000 and Windows XP systems as the primary fix.
  • If MSMQ is not required, disable or uninstall the Message Queuing service on affected hosts.
  • Block or restrict TCP port 2103 and MSMQ RPC traffic at network boundaries and host firewalls to trusted sources only.
  • Upgrade or retire Windows 2000 and Windows XP SP2 systems, which are long past end of support.
  • Limit authenticated access to MSMQ RPC interfaces to only the accounts and systems that require it.

Detection

  • Monitor network traffic to TCP port 2103 for oversized or malformed RPC opnum 0x06 requests.
  • Alert on MSMQ service crashes or unexpected restarts on Windows 2000 and XP hosts.
  • Review host logs for suspicious processes spawned by the MSMQ service account.
  • Use the OVAL definition referenced in the record to check for the missing patch.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/28011 Vendor Advisory
http://secunia.com/advisories/28051 Vendor Advisory
http://www.securityfocus.com/archive/1/484891/100/0/threaded
http://www.securityfocus.com/archive/1/485268/100/0/threaded
http://www.securityfocus.com/bid/26797
http://www.securitytracker.com/id?1019077
http://www.us-cert.gov/cas/techalerts/TA07-345A.html US Government Resource
http://www.vupen.com/english/advisories/2007/4181
http://www.zerodayinitiative.com/advisories/ZDI-07-076.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-065
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4474
https://www.exploit-db.com/exploits/4745
https://www.exploit-db.com/exploits/4760
https://www.exploit-db.com/exploits/4934
http://secunia.com/advisories/28011 Vendor Advisory
http://secunia.com/advisories/28051 Vendor Advisory
http://www.securityfocus.com/archive/1/484891/100/0/threaded
http://www.securityfocus.com/archive/1/485268/100/0/threaded
http://www.securityfocus.com/bid/26797
http://www.securitytracker.com/id?1019077
http://www.us-cert.gov/cas/techalerts/TA07-345A.html US Government Resource
http://www.vupen.com/english/advisories/2007/4181
http://www.zerodayinitiative.com/advisories/ZDI-07-076.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-065
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4474
https://www.exploit-db.com/exploits/4745
https://www.exploit-db.com/exploits/4760
https://www.exploit-db.com/exploits/4934

Track CVE-2007-3039 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed7.8CVE-2026-20700Apple OS memory corruption allows arbitrary code executionA memory corruption flaw caused by improper state management affects iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Apple states it is aware of a re…KEVEPSS 1.3%analysed8.8CVE-2025-14174Google Chrome ANGLE out-of-bounds memory access on MacChrome on macOS before 143.0.7499.110 contains an out-of-bounds memory access in the ANGLE graphics layer, classified as an out-of-bounds write (CWE-…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2007-3039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.