Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2024-49122

8.1HIGH

Key Information:

Vendor
Microsoft
Status
Windows 10 Version 1809
Windows Server 2019
Windows Server 2019 (server Core Installation)
Windows Server 2022
Vendor
CVE Published:
12 December 2024

Summary

This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to execute arbitrary code remotely on affected systems. By exploiting this flaw, malicious actors could potentially gain unauthorized access to sensitive data and execute further malicious activities within the network. This issue underscores the importance of ensuring that all software components are updated regularly to mitigate any potential risks associated with such vulnerabilities.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20857

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.7606

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.6659

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.