logo

Exploitation of Windows Server Update Services Remote Code Execution Vulnerability (CVE-2025-59287)

ID: 51f5831c-1d60-57a0-be45-85a97a3bee03

STIX ID: report--51f5831c-1d60-57a0-be45-85a97a3bee03

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-10-24

Date Updated: 2026-04-28

...
...

Huntress observed active exploitation of CVE-2025-59287, a WSUS AuthorizationCookie deserialization RCE, against WSUS instances exposed on default ports 8530/8531; attackers sent crafted POST requests to WSUS web services, spawned cmd.exe and powershell.exe via w3wp.exe/wsusservice.exe, decoded a base64 PowerShell payload to enumerate domain and network information (e.g., net user/domain, ipconfig/all) and exfiltrated results to a remote webhook, with observed use of proxy networks and approximately ~25 susceptible hosts across the partner base — organizations should apply Microsoft's out‑of‑band update immediately and review provided IOCs and WSUS logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.