CVE-2025-59287 Detection: A Critical Unauthenticated RCE Vulnerability in Microsoft WSUS Under Active Exploitation
ID: 4fe4d0ba-79e5-5a29-9d10-7d6bc43d14b7
STIX ID: report--4fe4d0ba-79e5-5a29-9d10-7d6bc43d14b7
Feed Name: SOC Prime Blog
Researchers and vendors have disclosed CVE-2025-59287, a critical (CVSS 9.8) unauthenticated RCE in Microsoft WSUS that is being actively exploited in the wild with public PoC available; the flaw stems from insecure BinaryFormatter deserialization in the WSUS ClientWebService and enables remote execution, persistence (webshells), multi-stage payload delivery, and C2 via processes such as w3wp.exe and wsusservice.exe. The report outlines multiple attack scenarios (PowerShell download-and-execute, webhook exfiltration, in-memory exfiltration, DNS beaconing), observed indicators (ports 8530/8531, dcrsproxy.exe, rcpkg.db, webhook.site), and recommends immediate application of Microsoft’s out-of-band patch or temporary mitigations (disable WSUS role or block ports).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
