Urgent Alert: Critical Microsoft WSUS Vulnerability (CVE-2025–59287) Actively Exploited — Patch Now!
A critical vulnerability in Microsoft’s Windows Server Update Service (WSUS), identified as CVE-2025–59287 (CVSS score: 9.8), is under…
Urgent Alert: Critical Microsoft WSUS Vulnerability (CVE-2025–59287) Actively Exploited — Patch Now!

patch-wsus
A critical vulnerability in Microsoft’s Windows Server Update Service (WSUS), identified as CVE-2025–59287 (CVSS score: 9.8), is under active exploitation in the wild. Microsoft has released emergency out-of-band security updates to address this remote code execution (RCE) flaw, which affects multiple Windows Server versions.
With a publicly available proof-of-concept (PoC) exploit and confirmed attacks, organizations must act swiftly to mitigate risks. This article explores the vulnerability, its implications, and actionable steps to secure your systems, optimized for search engines to ensure maximum visibility.
What is CVE-2025–59287?CVE-2025–59287 is a critical remote code execution vulnerability in WSUS, stemming from unsafe deserialization of untrusted data. The flaw allows unauthenticated attackers to execute malicious code over a network by exploiting a legacy serialization mechanism, specifically the BinaryFormatter, which lacks proper type validation.
This vulnerability grants attackers SYSTEM-level privileges, posing a severe risk to affected systems.The issue was initially addressed in Microsoft’s October 2025 Patch Tuesday update but required a re-released out-of-band patch on October 24, 2025, after the initial fix proved incomplete.
The vulnerability was discovered by security researchers MEOW, f7d8c52bec79e42795cf15888b85cbad, and Markus Wulftange of CODE WHITE GmbH.
Who is Affected?The vulnerability impacts the following Windows Server versions with the WSUS Server Role enabled:
- Windows Server 2012
- Windows Server 2012 R2
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
- Windows Server 2022, 23H2 Edition (Server Core)
- Windows Server 2025
Note: Servers without the WSUS Server Role enabled are not vulnerable. However, WSUS is commonly used in enterprise environments to manage updates, making this a significant concern for organizations with exposed WSUS instances.
How Attackers Exploit CVE-2025–59287The vulnerability arises from the unsafe deserialization of AuthorizationCookie objects sent to the WSUS GetCookie() endpoint. Attackers can craft malicious requests that trigger deserialization through BinaryFormatter, leading to RCE. According to HawkTrace security researcher Batuhan Er, the exploit involves:
- Sending encrypted cookie data to the GetCookie() endpoint.
- Decrypting the data using AES-128-CBC.
- Deserializing it without proper validation, enabling code execution with SYSTEM privileges.
Real-world attacks observed on October 24, 2025, involved a Base64-encoded .NET executable payload delivered via the “aaaa” request header. This payload executes commands through cmd.exe, avoiding direct logging to evade detection. Cybersecurity firms like Eye Security and Huntress reported exploitation attempts targeting WSUS instances exposed on default ports 8530/TCP and 8531/TCP.
Impact and Exploitation in the WildThe Dutch National Cyber Security Centre (NCSC) and Eye Security confirmed active exploitation starting at 06:55 a.m. UTC on October 24, 2025. Attackers leveraged exposed WSUS endpoints to deliver malicious payloads, including PowerShell scripts designed to enumerate network and user information and exfiltrate data to attacker-controlled servers.
Huntress noted that while WSUS is not commonly exposed publicly, the availability of a PoC exploit (released two days prior) and the simplicity of using standard ysoserial .NET payloads make this vulnerability highly exploitable. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025–59287 to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to remediate by November 14, 2025.
Mitigation and Remediation StepsTo protect against CVE-2025–59287, organizations should take the following actions immediately:
Apply the Out-of-Band Patch:
Install Microsoft’s emergency security update for affected Windows Server versions.
Reboot systems after applying the patch to ensure it takes effect.
Temporary Workarounds (if patching is delayed):
Disable the WSUS Server Role on affected servers.
Block inbound traffic to ports 8530 and 8531 using the host firewall.
Do not remove these workarounds until the patch is applied.
Monitor for Suspicious Activity:
Check for unusual cmd.exe or PowerShell processes spawned by WSUS.
Monitor network traffic to and from ports 8530 and 8531.
Follow Microsoft’s Guidance:
Refer to Microsoft’s official CVE page for detailed instructions: Microsoft CVE-2025–59287.
Why This MattersThe combination of a publicly available PoC exploit, active exploitation, and the potential for SYSTEM-level access makes CVE-2025–59287 a critical threat. Enterprises relying on WSUS for update management must prioritize patching to prevent data breaches, malware deployment, or network compromise. Microsoft’s decision to deprecate BinaryFormatter in .NET 9 (August 2024) underscores the inherent risks of legacy deserialization mechanisms, highlighting the need for modern security practices.
Best Practices for Ongoing Security
- Regular Patching: Ensure timely application of security updates to mitigate known vulnerabilities.
- Network Segmentation: Limit exposure of critical services like WSUS to the public internet.
- Endpoint Monitoring: Use security tools to detect and respond to suspicious activity in real time.
- Secure Development: Avoid unsafe deserialization methods like BinaryFormatter in applications.
CVE-2025–59287 is a stark reminder of the evolving threat landscape and the importance of proactive cybersecurity. With active exploitation underway and a PoC readily available, organizations must act swiftly to apply Microsoft’s out-of-band patch and implement recommended mitigations. By staying vigilant and prioritizing security updates, businesses can safeguard their systems against this critical WSUS vulnerability.For the latest updates, follow trusted sources like Microsoft’s Security Response Center, CISA, and cybersecurity firms like Huntress and Eye Security. Stay secure, patch now, and protect your network from emerging threats.
Source: https://thehackernews.com/2025/10/microsoft-issues-emergency-patch-for.html
메타데이터
- post_id
- 8d647402ac6e
- slug
- urgent-alert-critical-microsoft-wsus-vulnerability-cve-2025-59287-actively-exploited-patch-now-8d647402ac6e
- url
- https://medium.com/@costigermano/urgent-alert-critical-microsoft-wsus-vulnerability-cve-2025-59287-actively-exploited-patch-now-8d647402ac6e
- canonical_url
- https://medium.com/@costigermano/urgent-alert-critical-microsoft-wsus-vulnerability-cve-2025-59287-actively-exploited-patch-now-8d647402ac6e
- author_url
- https://medium.com/@costigermano
- status
- ok
- fetched_at
- 2026-06-21 19:25:17