CVE-2024-30080
Microsoft Message Queuing (MSMQ) has a critical remote code execution vulnerability (CVE-2024-30080) affecting numerous Windows 10, 11, and Server versions. The flaw stems from a use-after-free weakness (CWE-416) and can be reached over a network without authentication or user interaction.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Windows 10 (1507, 1607, 1809, 21H1), Windows 11 (21H2, 22H2, 23H2), and Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019, and 2022.
Real-world impact
If exploited, an attacker could run arbitrary code on affected systems with full control over confidentiality, integrity, and availability, potentially compromising entire networks.
Why this severity
Critical (CVSS 9.8) means the vulnerability is easy to exploit remotely and can cause severe damage without any privileges or user action.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jun 11, 2024 · Jun 11, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 17d agoAdvisory updatedThe NVD record was last revised.