Vulnerability record · CVE-2023-36606 · published 10 October 2023
CVE-2023-36606: Microsoft Message Queuing uncontrolled resource consumption denial of service
Microsoft · Windows 10
Microsoft Message Queuing (MSMQ) contains an uncontrolled resource consumption flaw (CWE-400) that allows a remote, unauthenticated attacker to cause a denial of service. The record provides only a one-line description and no technical detail on the specific resource exhausted or the trigger, so the exact mechanism is not documented here.
Description
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with a network, unauthenticated, no-interaction vector and a very high EPSS percentile make this a serious availability risk, though no confirmed exploitation is documented.
What it is
Microsoft Message Queuing (MSMQ) contains an uncontrolled resource consumption flaw (CWE-400) that allows a remote, unauthenticated attacker to cause a denial of service. The record provides only a one-line description and no technical detail on the specific resource exhausted or the trigger, so the exact mechanism is not documented here.
Impact
An attacker can degrade or halt MSMQ service availability on the affected host, disrupting message queuing for applications and services that depend on it. There is no confidentiality or integrity impact per the CVSS vector; the effect is availability loss.
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any host with the MSMQ service exposed can be targeted directly. The record does not state which MSMQ endpoints or ports are involved.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation activity is referenced; EPSS is high (0.67246, 99.266th percentile), indicating elevated predicted likelihood of exploitation despite the absence of confirmed in-the-wild use.
What to do
- Apply the Microsoft MSRC update for CVE-2023-36606 on all affected Windows client and server versions.
- Disable or stop the MSMQ service on hosts that do not require it, and block MSMQ-related network ports at the perimeter.
- Restrict network access to MSMQ endpoints to trusted hosts and segments only.
- Monitor MSMQ service health and resource usage so degradation is detected early.
- Prioritize internet-facing or otherwise exposed MSMQ hosts for patching first.
Detection
- Alert on MSMQ service crashes, restarts, or unexpected stops in Windows event logs.
- Monitor for abnormal memory, handle, or queue growth in the MSMQ service process.
- Baseline and alert on unusual inbound network traffic to MSMQ endpoints from untrusted sources.
- Correlate spikes in MSMQ-related resource consumption with availability failures on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36606 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36606 | PatchVendor Advisory |
Track CVE-2023-36606 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-36606), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.