logo

CVE-2025-59287 Explained: WSUS Unauthenticated RCE Vulnerability

ID: 156100f1-17f6-58a0-9a86-dd6d1a8592db

STIX ID: report--156100f1-17f6-58a0-9a86-dd6d1a8592db

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2025-10-25

Date Updated: 2026-07-22

Author: Picus Labs

...
...

On 24 Oct 2025 Microsoft issued an out-of-band patch for CVE-2025-59287, a critical (CVSS 9.8) unauthenticated RCE in Windows Server Update Services (WSUS) caused by unsafe .NET BinaryFormatter deserialization of AuthorizationCookie data; the report details the root cause, PoC payload generation and SOAP exploit, observed active exploitation against WSUS (ports 8530/8531), detection artifacts (logs, process chains), and recommends immediate patching, network restrictions and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.