Microsoft released an emergency out-of-band update to address a critical issue with Message Queuing (MSMQ) on Windows 10 systems, which emerged after the December 9, 2025, security updates. The bug caused MSMQ queues to become inactive, preventing applications from writing to queues and resulting in error messages related to insufficient resources, disk space, or memory. The problem was particularly severe in enterprise and clustered MSMQ environments, especially those running Internet Information Services (IIS) sites that rely on MSMQ for asynchronous processing, leading to potential service disruptions.
The out-of-band update (KB5074976) is available via the Microsoft Update Catalog and is not distributed through Windows Update or WSUS. Microsoft recommends that affected organizations, especially those with managed IT infrastructures or Azure-hosted devices, prioritize deploying the update and ensure the latest servicing stack update is installed to avoid deployment issues. Regular users with Windows Home or Pro editions are largely unaffected. Administrators are advised to test the patch in staging environments before production rollout to ensure stability and prevent further complications.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
On December 18, 2025, Microsoft acknowledged the MSMQ problems and released an out-of-band Windows 10 update, KB5074976, through the Update Catalog to fix the issue. The release was aimed primarily at enterprise and managed IT environments, and also included servicing stack update KB5068780.
Microsoft's December 9, 2025 Windows 10 security updates introduced a bug affecting Message Queuing (MSMQ), causing inactive queues, resource errors, and application failures. The issue particularly impacted enterprise clustered MSMQ deployments and IIS sites relying on MSMQ for asynchronous processing.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.