---
title: "Technical Advisory: Unauthorized RCE Vulnerability in MSMQ Service CVE-2023-21554 aka QueueJumper"
description: On April 11, 2023, Microsoft released a patch for a vulnerability in Microsoft Message Queuing (MSMQ) service. The CVE-2023-21554 vulnerability (dubbed QueueJumper) is a critical unauthorized remote code execution.
image: https://businessinsights.bitdefender.com/hubfs/QueueJumper.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

![QueueJumper](https://businessinsights.bitdefender.com/hubfs/QueueJumper.jpg)

[#Threat Research](https://businessinsights.bitdefender.com/topic/threat-research) [#Endpoint Detection and Response](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response) [#Managed Detection and Response](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)

 By [**Martin Zugec**](https://businessinsights.bitdefender.com/author/martin-zugec) / Apr 12, 2023

# Technical Advisory: Unauthorized RCE Vulnerability in MSMQ Service CVE-2023-21554 aka QueueJumper

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/technical-advisory-unauthorized-rce-vulnerability-in-msmq-service-cve-2023-21554-aka-queuejumper&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/technical-advisory-unauthorized-rce-vulnerability-in-msmq-service-cve-2023-21554-aka-queuejumper&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/technical-advisory-unauthorized-rce-vulnerability-in-msmq-service-cve-2023-21554-aka-queuejumper&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/technical-advisory-unauthorized-rce-vulnerability-in-msmq-service-cve-2023-21554-aka-queuejumper&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/technical-advisory-unauthorized-rce-vulnerability-in-msmq-service-cve-2023-21554-aka-queuejumper&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/technical-advisory-unauthorized-rce-vulnerability-in-msmq-service-cve-2023-21554-aka-queuejumper&utm_medium=social&utm_source=facebook)

On April 11, 2023, Microsoft released a patch for a vulnerability in Microsoft Message Queuing (MSMQ) service. [CVE-2023-21554](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21554) (dubbed **QueueJumper**) is a critical unauthorized remote code execution (RCE) vulnerability with a CVSS score of 9.8. Attack complexity is low, and it doesn’t require any privileges or user interaction. To exploit this vulnerability, threat actors would  send a malicious MSMQ packet to a listening MSMQ service. 

## What is MSMQ?

Microsoft Message Queueing is a technology that enables asynchronous communication between applications. It decouples sending and receiving components of a distributed system, making it a popular choice when designing applications that can support heterogenous networks and offline usage. While MSMQ can be considered a legacy technology, it is available on a wide range of Microsoft operating systems, including the latest build of Windows 11. MSMQ was commonly used as a middleware component of enterprise applications and is fully integrated with Microsoft’s .NET Framework.

![Graphical user interface, text, application
Description automatically generated](https://businessinsights.bitdefender.com/hubfs/undefined-Apr-12-2023-05-09-26-4570-PM.png)

Any vulnerability in a middleware component can have a cascading effect on other systems. We are releasing this technical advisory to help our customers identify potentially vulnerable systems and take proactive steps to mitigate this vulnerability. As of the writing of this advisory, there is no public proof of concept (POC) exploit available, and no actual incidents have been reported.

## Recommendations

It is strongly recommended to install [Microsoft's official patch](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21554) as soon as possible for this vulnerability. Legacy enterprise applications are often subject to delayed or skipped patches, but doing so can result in significant consequences. It is important to prioritize patching for systems that are accessible from the internet, but it is equally important not to overlook the need to patch internal-only systems. We have [previously documented](https://www.bitdefender.com/blog/businessinsights/tech-advisory-manageengine-cve-2022-47966/) the rising trend of weaponizing newly discovered vulnerabilities and opportunistic attacks, and this latest vulnerability has all the attributes that threat actors are looking for. Read more about [GravityZone Patch Management](https://www.bitdefender.com/content/dam/bitdefender/resources/technical-brief/Bitdefender-Patch-Management-Technical-Brief-en.pdf) to keep your systems up to date. 

Conduct an extensive infrastructure and software application audit to identify all systems where MSMQ is being deployed. To locate the vulnerable versions of MSMQ service in your environment, use the **Live Search** query feature of the GravityZone platform. With Live Search, you can retrieve information about events and system statistics directly from online endpoints using OSquery, an operating system instrumentation framework that uses the SQLite query language. This is currently available for customers that have enrolled in the Early Access program available in GravityZone Cloud. 

To enable Live Search - Log in to GravityZone. Click on your profile on the upper right side of the screen. From the drop-down menu, select My Company. Go to the Early Access tab. Select one of the programs available on the list. Click the Enroll below the table. Select Enroll to confirm. Your company will gain access to all the features, functionality, and interface changes included in the program. 

![](https://businessinsights.bitdefender.com/hubfs/undefined-Apr-12-2023-05-10-15-9634-PM.png)

To locate all running instances of mqsvc.exe, use the following query:

`SELECT processes.name, processes.path, listening_ports.port  FROM processes  JOIN listening_ports  ON listening_ports.pid = processes.pid  WHERE  processes.name = 'mqsvc.exe';`

![](https://businessinsights.bitdefender.com/hubfs/undefined-Apr-12-2023-05-11-59-4340-PM.png)

Actively monitor the infrastructure for potential exploitation attempts and respond accordingly. We strongly recommend implementing detection and response capabilities to detect any suspicious activity on the network and minimize the dwell time of adversaries. Bitdefender [GravityZone XDR](https://www.youtube.com/watch?v=ReBDrsyyiSY&ab_channel=BitdefenderEnterprise) sensors detect suspicious activity and alert security teams to lateral movement attempts or the establishment of an external connection by the threat actor. This technology can be augmented by good security operations, either in-house or through a managed service like [Bitdefender MDR](https://www.youtube.com/watch?v=TRp7uLYLGiQ). 

## **For the latest information on vulnerabilities such as this one,** [subscribe to Business Insights](https://www.bitdefender.com/blog/businessinsights/)**.**

 

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

### Explore More Topics

- [Enterprise Security (757)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (205)](https://businessinsights.bitdefender.com/topic/threat-research)
- [SMB Security (184)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [Ransomware (169)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (139)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (136)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (131)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (125)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (121)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (80)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (73)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (57)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (54)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (47)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (39)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (22)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (5)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/technical-advisory-cve-2022-30190-zero-day-vulnerability-follina-in-microsoft-support-diagnostic-tool?hsLang=en-us>

### [Technical Advisory: CVE-2022-30190 Zero-day Vulnerability “Follina” in Microsoft Support Diagnostic Tool](https://businessinsights.bitdefender.com/technical-advisory-cve-2022-30190-zero-day-vulnerability-follina-in-microsoft-support-diagnostic-tool?hsLang=en-us)

<https://businessinsights.bitdefender.com/bitdefender-threat-debrief-june-2022?hsLang=en-us>

### [Bitdefender Threat Debrief | June 2022](https://businessinsights.bitdefender.com/bitdefender-threat-debrief-june-2022?hsLang=en-us)

<https://businessinsights.bitdefender.com/cisa-urges-businesses-to-patch-domain-controller-netlogon-flaw?hsLang=en-us>

### [CISA Urges Businesses to Patch Domain Controller Netlogon Flaw](https://businessinsights.bitdefender.com/cisa-urges-businesses-to-patch-domain-controller-netlogon-flaw?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Martin Zugec",
    "url" : "https://businessinsights.bitdefender.com/author/martin-zugec"
  },
  "dateModified" : "2023-05-05T10:37:14.188Z",
  "datePublished" : "2023-04-12T17:55:44.000Z",
  "headline" : "Technical Advisory: Unauthorized RCE Vulnerability in MSMQ Service CVE-2023-21554 aka QueueJumper",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/QueueJumper.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/technical-advisory-unauthorized-rce-vulnerability-in-msmq-service-cve-2023-21554-aka-queuejumper",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```