CVE-2025-59287 Explained: WSUS Unauthenticated RCE Vulnerability
ID: 156100f1-17f6-58a0-9a86-dd6d1a8592db
STIX ID: report--156100f1-17f6-58a0-9a86-dd6d1a8592db
Feed Name: Resources-2
On 24 Oct 2025 Microsoft issued an out-of-band patch for CVE-2025-59287, a critical (CVSS 9.8) unauthenticated RCE in Windows Server Update Services (WSUS) caused by unsafe .NET BinaryFormatter deserialization of AuthorizationCookie data; the report details the root cause, PoC payload generation and SOAP exploit, observed active exploitation against WSUS (ports 8530/8531), detection artifacts (logs, process chains), and recommends immediate patching, network restrictions and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
