Vulnerability record · CVE-2023-21554 · published 11 April 2023
CVE-2023-21554: Microsoft Message Queuing improper input validation enables remote code execution
Microsoft · Windows 10 1607
CVE-2023-21554 is a remote code execution flaw in Microsoft Message Queuing (MSMQ) caused by improper input validation. It affects a broad set of Windows client and server versions, and because MSMQ is a network-facing service, an unauthenticated attacker can potentially reach it over the network. The record is thin: it provides no technical detail on the vulnerable code path or the specific malformed input required.
Description
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and a very high EPSS score make this a top patching priority despite the lack of confirmed in-the-wild exploitation in this record.
What it is
CVE-2023-21554 is a remote code execution flaw in Microsoft Message Queuing (MSMQ) caused by improper input validation. It affects a broad set of Windows client and server versions, and because MSMQ is a network-facing service, an unauthenticated attacker can potentially reach it over the network. The record is thin: it provides no technical detail on the vulnerable code path or the specific malformed input required.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the MSMQ service, which typically runs with elevated privileges on Windows servers. That can lead to full host compromise and lateral movement within the environment.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, meaning the flaw is reachable over the network with no authentication and no user interaction. The attack targets the MSMQ service directly, so any host with the Message Queuing feature enabled and reachable on its RPC or MSMQ ports is exposed.
Exploitation
The record does not list this CVE in CISA KEV and documents no ransomware use, but EPSS is very high at 0.95454 (99.866th percentile), indicating strong predicted likelihood of exploitation. The only references are Microsoft patch and advisory pages, so there is no confirmed public exploit information in this record.
What to do
- Apply the Microsoft security update for CVE-2023-21554 to all affected Windows versions as the first action.
- Disable the MSMQ service on hosts that do not require it, and remove the Message Queuing feature where it is unused.
- Restrict network access to MSMQ and its RPC endpoints with host firewall rules and network segmentation so only trusted systems can reach it.
- Monitor Microsoft advisories for updated guidance and re-check exposure after patching.
Detection
- Audit which hosts have the MSMQ service installed and running, and compare that inventory against business need.
- Monitor network traffic to MSMQ and RPC ports for unexpected external or cross-segment connections.
- Alert on MSMQ service crashes, restarts, or unusual child processes spawned by the MSMQ service account.
- Review Windows event logs and process creation telemetry for anomalous activity originating from the MSMQ service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21554 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21554 | PatchVendor Advisory |
Track CVE-2023-21554 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-21554), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.