A recent Microsoft security update released in December 2025 has caused significant issues with the Message Queuing (MSMQ) service on Windows 10 and older Windows Server versions. The update introduced changes to the MSMQ security model and NTFS permissions, specifically affecting the C:\Windows\System32\MSMQ\storage folder, which now requires write access for MSMQ users. As a result, MSMQ queues may become inactive, Internet Information Services (IIS) sites can fail with resource errors, and applications may be unable to write to queues, despite system resources being available. The issue primarily impacts enterprise and managed IT environments, especially those running clustered MSMQ under load, while personal devices are largely unaffected.
Administrators have reported a range of failures, including point-of-sale systems unable to issue receipts and building fire alarm systems going offline, potentially linked to the MSMQ malfunction. Microsoft has acknowledged the problem and suggested contacting their support team for a workaround, though some users have found that uninstalling the update resolves the issue. The lack of a detailed public workaround and the critical nature of affected applications have raised concerns among IT professionals about the reliability of recent security updates and the support process for urgent enterprise disruptions.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft confirmed the post-update MSMQ problem, said it was investigating, and advised affected customers to contact support for a workaround. It also noted that uninstalling the update could restore functionality, though doing so would remove the associated security fixes.
Following installation of the December 2025 update, Message Queuing queues became inactive on some systems, applications could no longer write to queues, and some IIS sites failed with resource errors. Reported impact included enterprise applications such as point-of-sale and fire alarm systems in managed IT environments.
Microsoft's December 2025 Patch Tuesday security update KB5071546 was released for certain Windows 10 and Windows Server versions. The update changed the MSMQ security model and NTFS permissions on the MSMQ storage directory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.