
Python proof of concept for CVE-2023-21554 (QueueJumper) in Microsoft MSMQ, constructing SRMP messages over TCP/1801 to verify the integer-overflow condition.
Proof of concept for CVE-2023-21554, also known as QueueJumper, affecting Microsoft Message Queuing (MSMQ).
The PoC implements the MSMQ/SRMP protocol interaction associated with the vulnerability and can be used to investigate the behavior of an MSMQ service over TCP/1801.
⚠️ For authorized security research only.
Run this PoC only against systems that you own or have explicit permission to test.
CVE-2023-21554 is a vulnerability affecting Microsoft Message Queuing (MSMQ).
This PoC constructs the relevant MSMQ/SRMP message structures and sends both a normal message and a malformed message containing the integer-overflow condition associated with the vulnerability.
The implementation checks the response for the MSMQ LIOR signature and reports the observed behavior.
The target is supplied dynamically from the command line rather than being hard-coded into the program.
LIOR response detectionThe PoC can be run from Linux, including Kali Linux.
Python 3 is required.
Check your version:
python3 --version
Download
Clone the repository
git clone https://github.com/YOUR_USERNAME/CVE-2023-21554-PoC.git
Enter the repository:
cd CVE-2023-21554-PoC
Make the script executable:
chmod +x poc.py
Usage
Display the available options:
python3 poc.py --help