The #QueueJumper MSMQ vuln is a great find. I don’t know if there’s much knowledge in InfoSec about MSMQ but it’s very widely used in middleware - eg pretty much all the main Siemens ICS products use it.
QueueJumper: Critical Unauthorized RCE Vulnerability in MSMQ Service
Check Point Research recently discovered three vulnerabilities in the "Microsoft Message Queuing" service, commonly known as MSMQ. These vulnerabilities were disclosed to Microsoft and patched in the April Patch Tuesday update. The most severe of these, dubbed QueueJumper by CPR (CVE-2023-21554), is a critical vulnerability that could allow unauthorized attackers to remotely execute arbitrary code in the context of the Windows service process mqsvc.exe.