Microsoft WSUS Remote Code Execution (CVE-2025-59287) Actively Exploited in the Wild (Updated November 3)
ID: 1dafdaae-bee6-5382-a44b-78f96719f26b
STIX ID: report--1dafdaae-bee6-5382-a44b-78f96719f26b
Feed Name: Palo Alto Networks Unit 42
Palo Alto Networks Unit 42 reports a critical unauthenticated RCE in Windows Server Update Services (CVE-2025-59287, CVSS 9.8) rooted in unsafe deserialization; Microsoft released an out-of-band patch after initial mitigation proved incomplete and researchers observed active exploitation targeting internet-exposed WSUS instances (ports 8530/8531), with attackers performing reconnaissance and exfiltration via PowerShell payloads. The brief provides technical attack paths, observed process chains and commands, ~5,500 exposed instances metric, interim mitigations (disable WSUS or block ports), XQL/XSOAR detection and response content, and a known IOC (webhook.site endpoint).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
