Microsoft disclosed and patched two denial-of-service flaws in Microsoft Message Queuing (MSMQ), tracked as CVE-2023-28302 and CVE-2023-36606, through its Security Update Guide. Both issues affect the Windows messaging component and could allow an attacker to disrupt service availability on systems where MSMQ is enabled.
The vulnerabilities were published in separate Microsoft advisories and add to the security risk surrounding exposed or unnecessary MSMQ deployments. Organizations using MSMQ should review Microsoft’s guidance, apply the relevant security updates, and verify whether the service is required on internet-facing or internal systems to reduce the likelihood of service disruption.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2023-36606, identifying it as a Microsoft Message Queuing (MSMQ) denial-of-service vulnerability.
Microsoft published a Security Update Guide entry for CVE-2023-28302, identifying it as a Microsoft Message Queuing (MSMQ) denial-of-service vulnerability.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.