CVE-2025-21270

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 400

Summary

CVE-2025-21270 is a denial-of-service (DoS) vulnerability affecting Microsoft Message Queuing (MSMQ). An attacker can exploit this issue by sending specially crafted messages to a MSMQ server, causing it to consume excessive system resources and ultimately leading to a denial-of-service condition. Successful exploitation does not grant the attacker unauthorized access or data exfiltration, but can render the MSMQ service unavailable. Microsoft recommends applying the available patch to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft