logo

Microsoft Releases Emergency Patch for Exploited Critical Remote Code Execution Vulnerability (CVE-2025-59287)

ID: 41141dd8-56b8-5967-88d5-003d7ae09d7b

STIX ID: report--41141dd8-56b8-5967-88d5-003d7ae09d7b

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2025-10-24

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On October 23, 2025 Microsoft released an out-of-band update for CVE-2025-59287, a critical unauthenticated deserialization RCE in WSUS (affecting servers with the WSUS role enabled). Arctic Wolf observed a campaign targeting WSUS servers on ports 8530/8531 where attackers executed PowerShell via IIS or wsusservice processes to run commands (net user/domain, ipconfig /all) and send output to actor-controlled endpoints; a public proof-of-concept and CISA KEV listing followed. Recommended mitigations include applying the latest Microsoft fixes, disabling WSUS or blocking ports 8530/8531 as a temporary workaround, and deploying monitoring (Arctic Wolf Agent/Sysmon) to detect related activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.