logo

How to find Microsoft Windows Server Update Services (WSUS) installations on your network

ID: 8667c717-c1ef-5fe5-9bff-99cb8f25b188

STIX ID: report--8667c717-c1ef-5fe5-9bff-99cb8f25b188

Feed Name: runZero Blog

Threat Score
90/100

Date Published: 2025-10-24

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

Microsoft disclosed CVE-2025-59287, a critical (CVSS 9.8) remote code execution vulnerability in Windows Server Update Services (WSUS) due to unsafe deserialization; the flaw allows unauthenticated remote attackers to execute arbitrary code, is reported to be actively exploited in the wild, affects multiple Windows Server releases (2012 through 2025), and Microsoft released out-of-band fixes (October 23, 2025) with recommended upgrade versions and a runZero query to locate potentially impacted assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.