CVE-2023-28302
published 2023-04-11CVE-2023-28302: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
93.56%
99.8th percentile
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_10_1809 | < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_10_20h2 | < 10.0.19042.2846 | 10.0.19042.2846 |
| microsoft | windows_10_21h2 | < 10.0.19044.2846 | 10.0.19044.2846 |
| microsoft | windows_10_22h2 | < 10.0.19045.2846 | 10.0.19045.2846 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19869 | 10.0.10240.19869 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2846 | 10.0.19042.2846 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2846 | 10.0.19044.2846 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2846 | 10.0.19045.2846 |
| microsoft | windows_11_21h2 | < 10.0.22000.1817 | 10.0.22000.1817 |
| microsoft | windows_11_22h2 | < 10.0.22621.1555 | 10.0.22621.1555 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1817 | 10.0.22000.1817 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1555 | 10.0.22621.1555 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26466 | 6.1.7601.26466 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.22015 | 6.0.6003.22015 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24216 | 6.2.9200.24216 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20919 | 6.3.9600.20919 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1668 | 10.0.20348.1668 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated inbound connections to TCP port 1801 — this is the exclusive attack vector for CVE-2023-28302 (kernel-level DoS / Windows BSOD) and the related MSMQ vulnerabilities. ↗
- →Alert on unexpected crashes or restarts of MQSVC.EXE, especially following inbound traffic on 1801/tcp, as exploitation of CVE-2023-28302 causes a Windows BSOD (kernel-level DoS). ↗
- →Use GreyNoise tags 'Microsoft Message Queueing (MSMQ) Crawler' and 'Microsoft Message Queueing (MSMQ) HTTP Crawler' to identify hosts scanning for exposed MSMQ instances on 1801/tcp. ↗
- →GreyNoise tag 'MICROSOFT MESSAGE QUEUING (MSMQ) QUEUEJUMPER RCE ATTEMPT | CVE-2023-21554' (classified malicious) can be used to detect active RCE exploitation attempts against MSMQ. ↗
- →Inspect MSMQ packet headers (BaseHeader, UserHeader, MessagePropertiesHeader, EodHeader) for malformed or unsanitized field values; CVE-2023-28302 is triggered by the message header parser routine in MQQM.DLL processing crafted packets. ↗
- ·CVE-2023-28302 only affects systems where the MSMQ service is explicitly installed/enabled; it is an optional Windows component and is not present by default. However, it may be silently enabled by third-party software installers (e.g., Microsoft Exchange Server). ↗
- ·As of late April 2023, GreyNoise observed no active RCE exploitation attempts in the wild for the related MSMQ CVEs, though scanning activity was ongoing. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j2x9-pqv3-56mg: Microsoft Message Queuing Denial of Service Vulnerability
ghsa_unreviewed·2023-04-11
CVE-2023-28302 [HIGH] CWE-20 GHSA-j2x9-pqv3-56mg: Microsoft Message Queuing Denial of Service Vulnerability
Microsoft Message Queuing Denial of Service Vulnerability
Microsoft
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
vendor_msrc·2023-04-11·CVSS 7.5
CVE-2023-28302 [HIGH] CWE-20 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Windows Active Directory: Windows Active Directory
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025229
Reference: https://support.microsoft.com/help/5025229
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025230
Reference: https://support.microsoft.com/help/5025230
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025221
Reference: https://support.microsoft.com/help/5025221
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025224
Refe
No detection rules found.
No public exploits indexed.
Fortinet
FortiGuard Labs Discovers Multiple Vulnerabilities in Microsoft Message Queuing Service | FortiGuard Labs
blogs_fortinet·2023-07-24
FortiGuard Labs Discovers Multiple Vulnerabilities in Microsoft Message Queuing Service | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
FortiGuard Labs Discovers Multiple Vulnerabilities in Microsoft Message Queuing Service
By Wayne Low | July 24, 2023
Over the last few months, FortiGuard Labs has discovered and reported multiple vulnerabilities found in the Microsoft Message Queuing (MSMQ) service. Microsoft patched these vulnerabilities in the April and July 2023 security updates. These patches are rated as critical/important, and as always, we urge users to install them as soon as possible.
Affected platforms: Windows
Impacted parties: Microsoft Windows users with Microsoft Message Queuing service installed
Impact: Remote code execution and denial-of-service
Severity level: Critical and Important
In this post, we will walk through the attack surfaces of MSMQ, the approaches we took to
Checkpoint
17th April – Threat Intelligence Report
blogs_checkpoint·2023-04-17
CVE-2023-28302 17th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th April, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Two major automotive manufacturers Hyundai and Toyota have disclosed significant data breaches. Hyundai’s Italian and French car owners were affected, along with individuals who booked a test drive. The leaked data consists of clients’ personal information including emails, addresses, phone numbers, and vehicle chassis numbers.
Checkpoint
QueueJumper: Critical Unauthenticated RCE Vulnerability in MSMQ Service
blogs_checkpoint·2023-04-11·CVSS 9.8
CVE-2023-21554 [CRITICAL] QueueJumper: Critical Unauthenticated RCE Vulnerability in MSMQ Service
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## QueueJumper: Critical Unauthenticated RCE Vulnerability in MSMQ Service
## Executive Summary
Check Point Research recently discovered three vulnerabilities in the “Microsoft Message Queu
Tenable
Microsoft’s April 2023 Patch Tuesday Addresses 97 CVEs (CVE-2023-28252)
blogs_tenable·2023-04-11·CVSS 7.8
[HIGH] Microsoft’s April 2023 Patch Tuesday Addresses 97 CVEs (CVE-2023-28252)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
GreyNoise| Trio Of Tags For Identifying Microsoft Message Queue Scanners And Exploiters Live Now
blogs_greynoiseio·CVSS 9.8
[CRITICAL] GreyNoise| Trio Of Tags For Identifying Microsoft Message Queue Scanners And Exploiters Live Now
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2023-04-11
Published