CVE-2023-21554 — Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5025234 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 for x64-based Systems | 5025234 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5025228 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5025228 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5025229 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 5025229 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5025229 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 20H2 for 32-bit Systems | 5025221 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 20H2 for ARM64-based Systems | 5025221 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5025221 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5025221 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5025221 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5025221 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5025221 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5025221 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5025224 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5025224 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5025239 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5025239 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5025271 (Monthly Rollup) 5025273 (Security Only) Critical Remote Code Execution 5023755 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5025271 (Monthly Rollup) 5025273 (Security Only) Critical Remote Code Execution 5023755 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 for x64-based Systems Service Pack 2 5025271 (Monthly Rollup) 5025273 (Security Only) Critical Remote Code Execution 5023755 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5025271 (Monthly Rollup) 5025273 (Security Only) Critical Remote Code Execution 5023755 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5025279 (Monthly Rollup) 5025277 (Security Only) Critical Remote Code Execution 5023769 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26466 Yes 5025279 5025277 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5025279 (Monthly Rollup) 5025277 (Security Only) Critical Remote Code Execution 5023769 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26466 Yes 5025279 5025277 Windows Server 2012 5025287 (Monthly Rollup) 5025272 (Security Only) Critical Remote Code Execution 5023769 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.24216 Yes None Windows Server 2012 (Server Core installation) 5025287 (Monthly Rollup) 5025272 (Security Only) Critical Remote Code Execution 5023769 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.24216 Yes None Windows Server 2012 R2 5025285 (Monthly Rollup) 5025288 (Security Only) Critical Remote Code Execution 5023765 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20919 Yes None Windows Server 2012 R2 (Server Core installation) 5025285 (Monthly Rollup) 5025288 (Security Only) Critical Remote Code Execution 5023765 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20919 Yes None Windows Server 2016 | 5025228 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5025228 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 | 5025229 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5025229 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2022 | 5025230 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2022 (Server Core installation) | 5025230 (Security Update) |
Critical | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5025234 |
Security Update | Yes |
5025228 |
Security Update | Yes |
5025229 |
Security Update | Yes |
5025221 |
Security Update | Yes |
5025224 |
Security Update | Yes |
5025239 |
Security Update | Yes |
5025230 |
Security Update | Yes |
Patch Diff
Patch diff 10.0.22621.963 -> 10.0.22621.1555 (MSMQ; safe section-pointer helpers across all header types)
| Function | Address | Change | Note |
|---|---|---|---|
KERNEL32.DLL::AcquireSRWLockExclusive |
EXTERNAL:0000011d -> EXTERNAL:00000113 |
refcount, address, calling | similarity 1.0 |
newstr |
1800a0d48 -> 1800a3208 |
length, address | similarity 1.0 |
wil_details_GetNtDllModuleHandle |
18005b828 -> 1800401c0 |
refcount, address, calling | similarity 1.0 |
CUserHeader::SectionIsValid |
18008426c -> 1800865f8 |
code, length, address, called | similarity 0.8 |
CDebugSection::SectionIsValid |
1800836d4 -> 1800858f0 |
code, length, address, called | similarity 0.43 |
CBaseMqfHeader::SectionIsValid |
1800834c0 -> 1800856a4 |
code, length, address, called | similarity 0.43 |
CXactHeader::SectionIsValid |
1800846c4 -> 180086a88 |
code, length, address, called | similarity 0.4 |
CMessageTransport::ReceiveResponseFailed |
1800a75b0 -> 1800a9a70 |
refcount, address | similarity 1.0 |
wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi'' |
180002680 -> 1800023f0 |
code, length, address | similarity 0.9 |
wil::details::StringCchPrintfA |
1800595c0 -> 18003e5f8 |
code, length, address, called | similarity 0.38 |
CPropertyHeader::SectionIsValid |
180083d74 -> 1800860a0 |
code, length, address, called | similarity 0.54 |
__GSHandlerCheck |
180004f48 -> 180004f98 |
refcount, address | similarity 1.0 |
_guard_xfg_dispatch_icall_nop |
1800df980 -> 1800e1e40 |
refcount, address, calling | similarity 0.89 |
atexit |
1800048ac -> 1800048fc |
refcount, address, calling | similarity 1.0 |
wil::details::unique_storage<wil::details::resource_policy<_TP_TIMER*___ptr64,void_(__cdecl*)(_TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),wistd::integral_constant<unsigned___int64,0>,_TP_TIMER*___ptr64,_TP_TIMER*___ptr64,0,std::nullptr_t>_>::reset |
18005b4a8 -> 18003f9b0 |
refcount, address, calling | similarity 1.0 |
__CxxFrameHandler4 |
180004744 -> 180004794 |
refcount, address | similarity 0.86 |
CQmPacket::CQmPacket |
1800377d8 -> 1800380ac |
code, length, address, called | similarity 0.31 |
GetSafeDataAndAdvancePointer<unsigned_long> |
180037328 -> 18003752c |
refcount, address, calling | similarity 1.0 |
wil::ProcessShutdownInProgress |
180056650 -> 18003c9d0 |
refcount, address, calling | similarity 1.0 |
CMsgDeadletterHeader::SectionIsValid |
180083a0c -> 180085cf0 |
code, length, address, called | similarity 0.41 |
KERNEL32.DLL::CreateThreadpoolTimer |
EXTERNAL:0000012a -> EXTERNAL:00000120 |
refcount, address, calling | similarity 1.0 |
CSSlNegotiation::Complete_ReadHandShakeResponse |
1800c8c30 -> 1800cb0f0 |
refcount, address | similarity 1.0 |
wistd::unique_ptr<void,wil::process_heap_deleter>::reset |
18005b484 -> 18003f98c |
refcount, address, calling | similarity 1.0 |
CUserHeader::QueueSize |
18003901c -> 18003cbe4 |
code, length, address, calling, called | similarity 0.76 |
CMsgGroupHeader::SectionIsValid |
180083b28 -> 180085e30 |
code, length, address, called | similarity 0.41 |
wil::details_abi::heap_buffer::push_back |
18005b1e0 -> 18003f884 |
refcount, address, calling | similarity 1.0 |
wil::details::EnsureCoalescedTimer_SetTimer |
180051c98 -> 18003a090 |
refcount, address, calling | similarity 1.0 |
StringCchVPrintfW |
18005963c -> 18003e644 |
code, length, address, called | similarity 0.39 |
ReportAndThrow |
180039154 -> 18003d930 |
refcount, address, calling | similarity 0.95 |
wil_details_GetKernelBaseModuleHandle |
18005b7f0 -> 180040188 |
refcount, address, calling | similarity 1.0 |
StringCchCopyA |
180049ecc -> 18003e5c0 |
code, refcount, length, address, called | similarity 0.42 |
KERNEL32.DLL::GetProcAddress |
EXTERNAL:00000109 -> EXTERNAL:00000110 |
refcount, address, calling | similarity 1.0 |
CSecurityHeader::SectionIsValid |
180083ec8 -> 180086224 |
code, length, address, called | similarity 0.77 |
wil::details::unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> |
18004fb04 -> 18003908c |
refcount, address, calling | similarity 1.0 |
wil::details::unique_storage<wil::details::resource_policy<_TP_TIMER*___ptr64,void_(__cdecl*)(_TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),wistd::integral_constant<unsigned___int64,0>,_TP_TIMER*___ptr64,_TP_TIMER*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_TP_TIMER*___ptr64,void_(__cdecl*)(_TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),wistd::integral_constant<unsigned___int64,0>,_TP_TIMER*___ptr64,_TP_TIMER*___ptr64,0,std::nullptr_t>_> |
18004fb54 -> 1800390dc |
refcount, address, calling | similarity 1.0 |
__GSHandlerCheck_EH4 |
1800df880 -> 1800e1d40 |
refcount, address | similarity 1.0 |
__security_check_cookie |
180004760 -> 1800047b0 |
refcount, address, calling | similarity 1.0 |
Attack Path
MSMQ section pointers computed by unchecked addition - a crafted packet walks the parser out of the buffer
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
5 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| zoemurmure/CVE-2023-21554-PoC | 59 | 2023-05-18 | CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/ |
| 3tternp/CVE-2023-21554 | 28 | 2023-08-17 | |
| leongxudong/MSMQ-Vulnerability | 5 | 2025-03-31 | Documentation and PoC for CVE-2023-21554 MSMQ Vulnerability |
| shootweb/CVE-2023-21554 | 2 | 2025-10-09 | CVE-2023-21554 PoC |
| Rahul-Thakur7/CVE-2023-21554 | 0 | 2024-12-16 |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 3
Acknowledgments
Haifei Li with Check Point Research
Wayne Low of Fortinet's FortiGuard Lab