CVE-2025-50177
8.1Microsoft · Windows Message Queuing
A use after free vulnerability in Windows Message Queuing enables an unauthenticated attacker to achieve remote code execution over a network.
Executive summary
A critical use after free vulnerability in Windows Message Queuing allows unauthenticated attackers to execute arbitrary code, posing a severe risk to system integrity.
Vulnerability
This flaw involves a use after free condition within the Windows Message Queuing service, compounded by a race condition. An unauthenticated attacker can exploit this memory corruption to achieve remote code execution.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with elevated system privileges. Given the CVSS score of 8.1, this represents a high-severity risk that could lead to total system compromise, unauthorized data access, and potential lateral movement within the corporate network.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official vendor advisory immediately.
Proactive Monitoring: Monitor network traffic for unusual patterns directed at the Message Queuing service and audit system logs for unexpected process execution.
Compensating Controls: Restrict network access to the Message Queuing service to trusted hosts only and utilize host-based firewalls to block unauthorized connections.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations should prioritize the deployment of the latest Microsoft security patches across all affected Windows environments. Due to the potential for remote code execution, delaying the application of these updates significantly increases the risk of system compromise. Ensure that all affected systems are brought up to the specified build versions to fully mitigate this vulnerability.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
- Fix documented version 10.0.10240.21100 per CVE record