Vulnerability record · CVE-2023-28302 · published 11 April 2023
CVE-2023-28302: Microsoft MSMQ improper input validation denial of service
Microsoft · Windows 10 1607
Microsoft Message Queuing (MSMQ) contains an improper input validation flaw that allows a remote, unauthenticated attacker to cause a denial of service. The vulnerability affects a broad range of Windows client and server releases, so any host with the MSMQ service enabled is exposed. Successful exploitation degrades or halts message queuing availability on the target.
Description
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote unauthenticated availability impact across many Windows versions with a very high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
Microsoft Message Queuing (MSMQ) contains an improper input validation flaw that allows a remote, unauthenticated attacker to cause a denial of service. The vulnerability affects a broad range of Windows client and server releases, so any host with the MSMQ service enabled is exposed. Successful exploitation degrades or halts message queuing availability on the target.
Impact
An attacker can crash or exhaust the MSMQ service, disrupting message delivery and dependent applications on the affected host. The CVSS vector shows availability impact only, with no confidentiality or integrity loss.
Attack surface
Reachable over the network (AV:N) with no privileges and no user interaction required (PR:N/UI:N), meaning the MSMQ service must be listening and reachable. No authentication is needed per the vector, though the record does not describe the exact protocol path or packet.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware association is recorded in the references, which are patch and vendor advisory only. EPSS is very high at 0.92573 (99.8th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply the Microsoft security update for CVE-2023-28302 on all affected Windows client and server versions.
- Disable or stop the MSMQ service on hosts that do not require it, and remove the MSMQ feature where unused.
- Restrict network access to MSMQ ports (for example TCP 1801 and RPC endpoints) to trusted hosts only.
- Monitor MSMQ service health and restart behavior for unexplained crashes or resource exhaustion.
- Inventory hosts running MSMQ to confirm patch coverage across the listed Windows 10, Windows 11 and Windows Server builds.
Detection
- Alert on unexpected MSMQ service crashes, restarts or stop events in the Windows System and Application logs.
- Monitor for spikes in MSMQ queue length, memory or handle usage that precede service failure.
- Baseline and review network connections to MSMQ listener ports from untrusted or unusual sources.
- Correlate Windows Update state against the affected build list to find unpatched MSMQ-enabled hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28302 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28302 | PatchVendor Advisory |
Track CVE-2023-28302 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-28302), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.