Microsoft disclosed and patched a cluster of Microsoft Message Queuing (MSMQ) denial-of-service vulnerabilities affecting Windows systems, including CVE-2025-21230, CVE-2025-21290, CVE-2025-21270, CVE-2025-21289, and CVE-2025-21251. The issues were published through the Microsoft Security Response Center update guide and all identify MSMQ as the affected component, indicating that specially crafted traffic or message handling conditions could disrupt the service and impact application availability on systems where MSMQ is enabled.
The January disclosures followed an earlier MSMQ denial-of-service issue, CVE-2024-49096, showing continued security attention on the legacy messaging component across consecutive update cycles. Organizations using MSMQ should prioritize applying Microsoft security updates, verify whether the service is enabled on exposed or business-critical hosts, and assess operational dependencies because repeated flaws in the component raise the risk of service interruption if unpatched systems remain reachable.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft released Security Update Guide entries for CVE-2025-21230, CVE-2025-21290, CVE-2025-21270, CVE-2025-21289, and CVE-2025-21251, all described as Microsoft Message Queuing (MSMQ) denial-of-service vulnerabilities.
Microsoft published a Security Update Guide entry for CVE-2024-49096, identifying a denial-of-service vulnerability in Microsoft Message Queuing (MSMQ).
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.