Microsoft Releases Emergency Patch for Exploited Critical Remote Code Execution Vulnerability (CVE-2025-59287)
ID: 41141dd8-56b8-5967-88d5-003d7ae09d7b
STIX ID: report--41141dd8-56b8-5967-88d5-003d7ae09d7b
Feed Name: Arctic Wolf
On October 23, 2025 Microsoft released an out-of-band update for CVE-2025-59287, a critical unauthenticated deserialization RCE in WSUS (affecting servers with the WSUS role enabled). Arctic Wolf observed a campaign targeting WSUS servers on ports 8530/8531 where attackers executed PowerShell via IIS or wsusservice processes to run commands (net user/domain, ipconfig /all) and send output to actor-controlled endpoints; a public proof-of-concept and CISA KEV listing followed. Recommended mitigations include applying the latest Microsoft fixes, disabling WSUS or blocking ports 8530/8531 as a temporary workaround, and deploying monitoring (Arctic Wolf Agent/Sysmon) to detect related activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
