CVE-2025-59287

9.5 CISA KEV

Microsoft · Windows Server Update Service

A deserialization of untrusted data vulnerability in Microsoft Windows Server Update Service allows unauthenticated attackers to execute arbitrary code over the network.

Executive summary

This critical vulnerability in Microsoft Windows Server Update Service is actively exploited in the wild and allows unauthenticated remote code execution.

Vulnerability

This is a deserialization of untrusted data flaw (CWE-502) within the Windows Server Update Service. It enables an unauthenticated attacker to achieve remote code execution by sending specifically crafted network requests to the vulnerable service.

Business impact

The potential for unauthenticated remote code execution represents the highest possible level of risk to organizational infrastructure. Given the CVSS score of 9.5 and evidence of active exploitation, this flaw could lead to total system compromise, exfiltration of sensitive data, and the lateral movement of attackers throughout the internal network. Failure to remediate this vulnerability immediately exposes the organization to significant operational disruption and data breach risks.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to all affected Windows Server instances.

Proactive Monitoring: Monitor network traffic for anomalous inbound requests targeting WSUS ports and review system logs for unexpected child processes spawned by the WSUS service.

Compensating Controls: Implement strict network access control lists to limit access to WSUS services to authorized management subnets only, reducing the attack surface while patches are deployed.

Exploitation status

Public Exploit Available: Yes, a Metasploit module is available, and numerous proof of concept repositories exist on GitHub.

Analyst recommendation

Due to the critical severity and confirmed active exploitation of this vulnerability, immediate patching is required. Organizations should prioritize the deployment of the vendor-supplied updates to all exposed Windows Server systems. If patching is not immediately feasible, isolate affected systems from the network until the remediation can be verified and applied.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section, carried in 2 daily briefs, Oct 14 to Oct 15
  3. Published in the daily brief kev section, carried in 21 daily briefs, Oct 24 to Nov 13
  4. Look Back published
  5. Analyst report written
  6. Fix documented version 6.2.9200.25728 per CVE record

Sources