CVE-2025-21277
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-21277 is a Denial of Service (DoS) vulnerability affecting Microsoft Message Queuing (MSMQ). An attacker can exploit this issue by sending maliciously crafted messages to an MSMQ queue, leading to a memory leak and subsequent system instability. As a result, the MSMQ service may become unresponsive or crash, disrupting the messaging system and potentially impacting business operations. Microsoft has released a security update to address this vulnerability. It is recommended that organizations apply the update as soon as possible to mitigate the risk of a DoS attack.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
Affected Vendors
- Microsoft