CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
In short
Windows Server Update Service (WSUS) incorrectly processes untrusted data from the network, allowing attackers to execute arbitrary code on the server without authentication. This is a critical flaw because WSUS is often trusted to manage security updates across entire organizations.
Technical detail
CWE-502 deserialization vulnerability in WSUS enables remote code execution via malicious network packets. The attack requires network access to the WSUS service but no authentication; exploitation results in complete system compromise with the privileges of the WSUS process.
Summary generated and translated by AI from the official description.
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Affected products
Microsoft · Windows Server 2012Microsoft · Windows Server 2012 R2Microsoft · Windows Server 2012 R2 (Server Core installation)Microsoft · Windows Server 2012 (Server Core installation)Microsoft · Windows Server 2016Microsoft · Windows Server 2016 (Server Core installation)Microsoft · Windows Server 2019Microsoft · Windows Server 2019 (Server Core installation)Microsoft · Windows Server 2022Microsoft · Windows Server 2022, 23H2 Edition (Server Core installation)Microsoft · Windows Server 2025Microsoft · Windows Server 2025 (Server Core installation)public PoCs found — 8
githubgithub.com/M507/CVE-2025-59287-PoC★ 13githubgithub.com/LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE★ 2githubgithub.com/Twodimensionalitylevelcrossing817/CVE-2025-59287★ 1githubgithub.com/Adel-kaka-dz/cve-2025-59287★ 1githubgithub.com/swoon69/CVE-2025-59287-Exercise-Use★ 0githubgithub.com/gud425/gud425.github.io★ 0githubgithub.com/ross-ns/WSUS-CVE-2025-59287★ 0cve_referencegist.github.com/hawktrace/880b54fb9c07ddb028baaae401bd3951unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://gist.github.com/hawktrace/880b54fb9c07ddb028baaae401bd3951https://hawktrace.com/blog/CVE-2025-59287https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windows-server-wsus-flaw-exploited-in-attacks/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59287https://www.vicarius.io/vsociety/posts/cve-2025-59287-detection-script-rce-vulnerability-in-windows-server-update-servicehttps://www.vicarius.io/vsociety/posts/cve-2025-59287-mitigation-script-rce-vulnerability-in-windows-server-update-service