logo

Microsoft Issues Emergency Patch for Windows Server Update Services RCE Vulnerability CVE-2025-59287

ID: db40ff5e-b308-5fce-9661-64b4fd32119e

STIX ID: report--db40ff5e-b308-5fce-9661-64b4fd32119e

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
90/100

Date Published: 2025-11-14

Date Updated: 2026-04-28

Author: Fernando Martinez

...
...

LevelBlue Labs describes `CVE-2025-59287`, a deserialization RCE in Windows Server Update Services (WSUS) that enables unauthenticated attackers to execute code as SYSTEM; Microsoft issued an initial and an out-of-band patch and CISA added the CVE to its Known Exploited Vulnerabilities catalog after observed in-the-wild attacks. The report provides detection rules, IOCs, mitigation guidance (apply updates, disable WSUS or block ports), and mapped MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.