CVE-2025-21270
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 400
Summary
CVE-2025-21270 is a denial-of-service (DoS) vulnerability affecting Microsoft Message Queuing (MSMQ). An attacker can exploit this issue by sending specially crafted messages to a MSMQ server, causing it to consume excessive system resources and ultimately leading to a denial-of-service condition. Successful exploitation does not grant the attacker unauthorized access or data exfiltration, but can render the MSMQ service unavailable. Microsoft recommends applying the available patch to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
Affected Vendors
- Microsoft