logo

Windows Server emergency patches fix WSUS bug with PoC exploit

ID: bcc2bc8a-b4b1-55f9-b68b-3e1cccdd5159

STIX ID: report--bcc2bc8a-b4b1-55f9-b68b-3e1cccdd5159

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-24

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Microsoft released out-of-band patches for CVE-2025-59287, a critical unauthenticated remote code execution vulnerability in WSUS that can allow attackers to run code as SYSTEM and may be wormable between WSUS servers; a public proof-of-concept is available, and Microsoft advises immediate patching or temporary mitigations (disable WSUS role or block ports 8530/8531).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.