QueueJumper (CVE-2023-21554) is a critical remote code execution vulnerability in Microsoft Message Queuing (MSMQ). An unauthenticated attacker can send a specially crafted MSMQ packet to a host running the Message Queuing service and cause arbitrary code execution in the context of the mqsvc.exe service process. The vulnerability is reachable through the MSMQ listener on TCP port 1801 when MSMQ is installed and enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a proof-of-concept (PoC) exploit for CVE-2023-21554, a vulnerability in Microsoft Message Queuing (MSMQ) on Windows. The main script, CVE-2023-21554.py, is a Python 3 program that sends three crafted binary payloads (establish_connection.bin, connection_parameters.bin, user_message.bin) in sequence to a target host's MSMQ service on TCP port 1801. The script logs detailed information about server responses, including hexdumps, connection resets, and timing, to help determine if the target is vulnerable (e.g., by observing service crashes or abnormal socket behavior). The repository is structured with the main exploit script, a README with detailed usage and evidence collection instructions, and a license file. The exploit is network-based, requires the attacker to have access to the target's MSMQ port, and is intended for use in controlled lab environments for vulnerability verification and analysis. No post-exploitation or weaponized payload is included; the PoC is focused on triggering and detecting the vulnerability.
This repository targets CVE-2023-21554, a critical unauthenticated remote code execution vulnerability in Microsoft Message Queuing (MSMQ) service (mqsvc.exe) on TCP port 1801. The main exploit is implemented in 'poc.py', a Python script that connects to a user-specified IP address on port 1801 and sends a sequence of three binary payloads: 'establish_connection.bin', 'connection_parameters.bin', and 'user_message.bin'. These payloads are designed to interact with the MSMQ protocol and potentially trigger the vulnerability, leading to remote code execution. The repository also includes detailed markdown documentation on detection and mitigation strategies, as well as references to official advisories and technical resources. The exploit is a proof-of-concept and requires the target to have MSMQ enabled and accessible. No weaponized or framework-based code is present; the exploit is standalone and relies on external binary payloads for its operation.
This repository is a proof-of-concept (PoC) exploit for CVE-2023-21554, a vulnerability in Microsoft Windows Message Queuing (MSMQ). The repository contains two files: a README.md with usage instructions and a Python script (poc.py) that implements the exploit logic. The exploit works by sending a sequence of crafted binary payloads (which must be provided in a local .\data\ directory) to the target's MSMQ service over TCP port 1801. The user must set the target IP address in the script. Successful exploitation results in a crash of the mqsvc.exe process on the target, causing a denial of service. The exploit does not provide a shell or code execution, only a process crash. The code is straightforward and intended for research or demonstration purposes.
This repository provides a proof-of-concept (PoC) exploit for CVE-2023-21554, a vulnerability in Microsoft Windows Message Queuing (MSMQ). The exploit consists of a Python script (poc.py) and a README.md with usage instructions. The script prompts the user for a target IP address, then connects to TCP port 1801 (the default MSMQ port) on the target. It sends a sequence of crafted binary messages (which must be present in a local .\data\ directory) to the service. If the exploit is successful, it causes the mqsvc.exe process on the target to crash, resulting in a denial-of-service. The exploit does not provide remote code execution or shell access, but demonstrates the vulnerability by crashing the service. The repository is structured simply, with the main entry point being poc.py, and relies on external binary files for the crafted payloads.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical remote code execution vulnerability in the Microsoft Message Queuing (MSMQ) service that could allow attackers to execute arbitrary code on affected systems.
Windows MSMQ remote code execution vulnerability referenced as previously patched in 2023.
A critical unauthenticated remote-code-execution vulnerability in Microsoft Message Queuing (MSMQ). An attacker can send a specially crafted packet to TCP port 1801 to execute code in the MSMQ service process.
A critical remote code execution vulnerability in Microsoft Message Queuing (MSMQ) exploitable via specially crafted MSMQ packets when the service is enabled (TCP/1801).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.