Vulnerability record · CVE-2007-3039 · published 12 December 2007
CVE-2007-3039: Microsoft MSMQ RPC Stack Buffer Overflow Enables Remote Code Execution
Microsoft · Message Queuing
The Microsoft Message Queuing (MSMQ) service contains a stack-based buffer overflow triggered by a long string in an opnum 0x06 RPC call to port 2103. A remote attacker who can reach that RPC interface can corrupt memory and execute arbitrary code in the service context. The flaw affects Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2, and is noted as remotely exploitable on Windows 2000 Server.
Description
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
AV:N/AC:L/Au:S/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is a remotely reachable, pre-authentication-adjacent memory corruption with public exploit code and very high EPSS, but it is limited to legacy Windows 2000 and XP SP2 systems that are largely out of support.
What it is
The Microsoft Message Queuing (MSMQ) service contains a stack-based buffer overflow triggered by a long string in an opnum 0x06 RPC call to port 2103. A remote attacker who can reach that RPC interface can corrupt memory and execute arbitrary code in the service context. The flaw affects Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2, and is noted as remotely exploitable on Windows 2000 Server.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the MSMQ service, which on Windows 2000 Server can mean full control of the host. That allows data theft, service disruption, or use of the machine as a foothold for further network activity.
Attack surface
The vulnerability is reached over the network through an RPC call to port 2103 using opnum 0x06. The CVSS vector indicates authentication is required (Au:S), and no user interaction is described.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.69055 (99.3rd percentile), and multiple public Exploit-DB entries exist, indicating mature public exploit code. No ransomware association is documented.
What to do
- Apply Microsoft security bulletin MS07-065 to affected Windows 2000 and Windows XP systems as the primary fix.
- If MSMQ is not required, disable or uninstall the Message Queuing service on affected hosts.
- Block or restrict TCP port 2103 and MSMQ RPC traffic at network boundaries and host firewalls to trusted sources only.
- Upgrade or retire Windows 2000 and Windows XP SP2 systems, which are long past end of support.
- Limit authenticated access to MSMQ RPC interfaces to only the accounts and systems that require it.
Detection
- Monitor network traffic to TCP port 2103 for oversized or malformed RPC opnum 0x06 requests.
- Alert on MSMQ service crashes or unexpected restarts on Windows 2000 and XP hosts.
- Review host logs for suspicious processes spawned by the MSMQ service account.
- Use the OVAL definition referenced in the record to check for the missing patch.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3039 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.