CVE-2023-21554

CRITICAL

CVE-2023-21554 - QueueJumper - MSMQ RCE Check

Title source: metasploit

Description

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Exploits (6)

nomisec WORKING POC 57 stars
by zoemurmure · poc
https://github.com/zoemurmure/CVE-2023-21554-PoC
nomisec WORKING POC 24 stars
by 3tternp · poc
https://github.com/3tternp/CVE-2023-21554
nomisec WORKING POC 5 stars
by leongxudong · poc
https://github.com/leongxudong/MSMQ-Vulnerability
nomisec WORKING POC
by shootweb · poc
https://github.com/shootweb/CVE-2023-21554
nomisec WORKING POC
by Rahul-Thakur7 · poc
https://github.com/Rahul-Thakur7/CVE-2023-21554
metasploit SCANNER
by Wayne Low, Haifei Li, Bastian Kanbach <[email protected]> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/msmq/cve_2023_21554_queuejumper.rb

Scores

CVSS v3 9.8
EPSS 0.9190
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (14)
microsoft/windows_10_1607 < 10.0.14393.5850
microsoft/windows_10_1809 < 10.0.17763.4252
microsoft/windows_10_20h2 < 10.0.19042.2846
microsoft/windows_10_21h2 < 10.0.19044.2846
microsoft/windows_10_22h2 < 10.0.19045.2846
microsoft/windows_11_21h2 < 10.0.22000.1817
microsoft/windows_11_22h2 < 10.0.22621.1555
microsoft/windows_server_2008
microsoft/windows_server_2008 r2 sp1
microsoft/windows_server_2012
... and 4 more
Published Apr 11, 2023
Tracked Since Feb 18, 2026