CVE-2025-21289

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 400

Summary

CVE-2025-21289 is a Denial of Service (DoS) vulnerability affecting Microsoft Message Queuing (MSMQ). An attacker can exploit this issue by sending specially crafted messages to a MSMQ server, leading to a resource exhaustion condition. This can result in the MSMQ service becoming unresponsive or crashing, causing a denial of service to the affected system. Microsoft recommends installing the latest patch to address this vulnerability and advises implementing network protections to prevent attackers from sending malicious messages to MSMQ servers.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft