logo

A Vulnerability in Microsoft Windows Server Update Services (WSUS) Could Allow for Remote Code Execution

ID: 92291d00-8c35-5d17-a352-8e7dd1c300fd

STIX ID: report--92291d00-8c35-5d17-a352-8e7dd1c300fd

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2025-10-24

Date Updated: 2026-04-27

...
...

A critical deserialization vulnerability (CVE-2025-59287) in Microsoft WSUS allows unauthenticated remote code execution via a specially crafted event sent to the WSUS server. If exploited, an attacker could gain full control of the WSUS server and distribute malicious updates to client devices; no user interaction is required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.