Microsoft Released Out-of-band Update to Fix MSMQ Bug that Impacts IIS Sites
Microsoft has released an emergency update to resolve a critical issue affecting Message Queuing (MSMQ) functionality following the security patches issued on Dec 9, 2025.
Microsoft has released an emergency update to resolve a critical issue affecting Message Queuing (MSMQ) functionality following the security patches issued on Dec 9, 2025.
The update, available as of Dec 18, 2025, is applicable to Windows 10 versions 22H2 and 21H2, specifically OS Builds 19044.6693 and 19045.6693.
The MSMQ vulnerability, identified after the installation of the previous updates, causes message queues to become inactive, preventing applications from writing to these queues. This problem is particularly severe in clustered MSMQ environments under heavy load.
Internet Information Services (IIS) sites relying on MSMQ for asynchronous message processing may experience service disruptions without this patch.
While enterprise environments and managed IT infrastructures are primarily impacted, most personal Windows Home and Pro editions remain unaffected.
The update, available as of Dec 18, 2025, is applicable to Windows 10 versions 22H2 and 21H2, specifically OS Builds 19044.6693 and 19045.6693.
The Dec 18 update includes all fixes from the previous Dec 9 release, offering cumulative improvements for users who have not yet applied the earlier patches.
An additional servicing stack update (KB5068780) is included to enhance verification logic for Azure-hosted devices, ensuring seamless future update installations on cloud infrastructure.
Microsoft advises installing the latest servicing stack update before applying further patches to avoid deployment complications. Azure customers must ensure device access to certificate update domains for successful installation.
Organizations using IIS with MSMQ integration should test the patch in staging environments before deploying it to production. The update is available via Windows Update, Business Update Catalog, and Server Update Services channels.
Microsoft has also announced that Secure Boot certificates will expire starting in June 2026, potentially affecting device boot capabilities. Organizations should review certificate guidance and schedule updates proactively to prevent operational disruptions.
Based on reporting by Cyber Security News.
