Vulnerability record · CVE-2023-21769 · published 11 April 2023
CVE-2023-21769: Microsoft MSMQ out-of-bounds read causes denial of service
Microsoft · Windows 10 1607
CVE-2023-21769 is a denial of service flaw in Microsoft Message Queuing (MSMQ) on multiple Windows client and server versions. It is classified as an out-of-bounds read (CWE-125), though NVD also notes insufficient information on the root cause. Because MSMQ is a network-facing service, an unauthenticated remote attacker can disrupt message queuing availability.
Description
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated availability impact across a wide range of Windows versions, with very high EPSS despite no KEV listing.
What it is
CVE-2023-21769 is a denial of service flaw in Microsoft Message Queuing (MSMQ) on multiple Windows client and server versions. It is classified as an out-of-bounds read (CWE-125), though NVD also notes insufficient information on the root cause. Because MSMQ is a network-facing service, an unauthenticated remote attacker can disrupt message queuing availability.
Impact
Successful exploitation causes a denial of service, taking down or degrading the MSMQ service on the target host. The CVSS vector shows no confidentiality or integrity impact, only availability (A:H).
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any host exposing MSMQ can be targeted remotely. No authentication is required per the vector.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is very high at 0.887 (99.8th percentile), indicating elevated predicted exploitation activity. The only references are the Microsoft patch advisory.
What to do
- Apply the Microsoft security update for CVE-2023-21769 on all affected Windows versions listed in the advisory.
- If MSMQ is not required, disable or uninstall the Message Queuing feature to remove the attack surface.
- Restrict network access to MSMQ ports (for example TCP 1801 and RPC endpoints) to trusted hosts only.
- Monitor vendor guidance for any updated fixes or workarounds if patching is delayed.
Detection
- Monitor MSMQ service crashes or unexpected restarts in Windows event logs and service control manager logs.
- Alert on anomalous inbound traffic to MSMQ-related ports from untrusted sources.
- Correlate host availability drops on systems running the Message Queuing role with network connection attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21769 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21769 | PatchVendor Advisory |
Track CVE-2023-21769 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-21769), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.