Microsoft patched CVE-2023-21554, dubbed QueueJumper, a critical unauthenticated remote-code-execution vulnerability in Microsoft Message Queuing (MSMQ). An attacker can exploit the flaw through TCP port 1801 to execute code in the mqsvc.exe service context, potentially enabling remote compromise of affected Windows systems where MSMQ is enabled.
Organizations should apply Microsoft’s April 2023 security updates. Where patching cannot occur immediately, defenders should disable MSMQ when it is not required or block untrusted inbound traffic to TCP port 1801; the same update release also remediated the actively exploited CLFS elevation-of-privilege flaw CVE-2023-28252, which had been used to obtain SYSTEM privileges in Nokoyawa ransomware attacks.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Two days after the April Patch Tuesday release, Wiz Research reported that 84% of surveyed cloud environments had not installed the latest KB updates, leaving 16% protected against both CVE-2023-21554 and CVE-2023-28252.
Microsoft's April 2023 Patch Tuesday fixed 97 vulnerabilities, including the critical MSMQ remote-code-execution flaw CVE-2023-21554 (QueueJumper) and CVE-2023-28252, a CLFS privilege-escalation zero-day actively used to deploy Nokoyawa ransomware.
The Nokoyawa ransomware group began using other exploits targeting the Windows Common Log File System (CLFS), which were attributed to a single exploit developer.
Nokoyawa ransomware first emerged, targeting 64-bit Windows systems and using double extortion against victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.