Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2024-49118
8.1HIGH
Summary
A remote code execution vulnerability exists in Microsoft Message Queuing (MSMQ) when the software fails to properly handle objects in memory. This can allow an attacker to execute arbitrary code in the context of the target user. Exploitation of this vulnerability requires that a user open a specially crafted message. Microsoft has issued an advisory detailing the issue and recommends applying security updates to mitigate potential risks.
Affected Version(s)
Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20857
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.7606
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.6659
References
EPSS Score
0% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre DatabaseMicrosoft Feed