Windows Server emergency patches fix WSUS bug with PoC exploit
ID: bcc2bc8a-b4b1-55f9-b68b-3e1cccdd5159
STIX ID: report--bcc2bc8a-b4b1-55f9-b68b-3e1cccdd5159
Feed Name: Bleeping Computer
Threat Score
Microsoft released out-of-band patches for CVE-2025-59287, a critical unauthenticated remote code execution vulnerability in WSUS that can allow attackers to run code as SYSTEM and may be wormable between WSUS servers; a public proof-of-concept is available, and Microsoft advises immediate patching or temporary mitigations (disable WSUS role or block ports 8530/8531).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
