← back
CVE-2025-59287

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVSS 9.8 CRITICALEPSS 100.0%● KEVCWE-502
In short

Windows Server Update Service (WSUS) incorrectly processes untrusted data from the network, allowing attackers to execute arbitrary code on the server without authentication. This is a critical flaw because WSUS is often trusted to manage security updates across entire organizations.

Technical detail

CWE-502 deserialization vulnerability in WSUS enables remote code execution via malicious network packets. The attack requires network access to the WSUS service but no authentication; exploitation results in complete system compromise with the privileges of the WSUS process.

Summary generated and translated by AI from the official description.
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →