Microsoft Issues Emergency Patch for Windows Server Update Services RCE Vulnerability CVE-2025-59287
ID: db40ff5e-b308-5fce-9661-64b4fd32119e
STIX ID: report--db40ff5e-b308-5fce-9661-64b4fd32119e
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
LevelBlue Labs describes `CVE-2025-59287`, a deserialization RCE in Windows Server Update Services (WSUS) that enables unauthenticated attackers to execute code as SYSTEM; Microsoft issued an initial and an out-of-band patch and CISA added the CVE to its Known Exploited Vulnerabilities catalog after observed in-the-wild attacks. The report provides detection rules, IOCs, mitigation guidance (apply updates, disable WSUS or block ports), and mapped MITRE ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
