← Vulnerability feed

Vulnerability record · CVE-2025-59287 · published 14 October 2025

CVE-2025-59287: Microsoft WSUS deserialization flaw allows unauthenticated remote code execution

Microsoft · Windows Server 2012

Windows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rated CVSS 9.8 critical and affects WSUS on Windows Server 2012 through 2025. Because WSUS is a central patch-distribution role, compromise of that host can affect the whole managed estate.

9.8 CVSS 3.1 Critical CISA KEV since 24 Oct 2025 EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
7References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network RCE, KEV listing with a federal remediation deadline, and near-maximum EPSS make this an urgent patch-first item.

What it is

Windows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rated CVSS 9.8 critical and affects WSUS on Windows Server 2012 through 2025. Because WSUS is a central patch-distribution role, compromise of that host can affect the whole managed estate.

Impact

An attacker gains remote code execution on the WSUS server with no credentials, giving full control of the host (high confidentiality, integrity and availability impact). From there they can tamper with updates distributed to managed endpoints.

Attack surface

Reachable over the network (AV:N) with no privileges and no user interaction (PR:N, UI:N), so any host that can reach the WSUS service can attempt it. No authentication is required per the vector and description.

Exploitation

CISA added it to KEV on 2025-10-24 with a 2025-11-14 remediation due date, and references include an exploit write-up and press reporting of attacks in the wild. EPSS is 0.9998 (99.98th percentile), indicating very high predicted exploitation activity.

What to do

  • Apply the Microsoft security update for CVE-2025-59287 to all WSUS servers immediately, per the vendor advisory.
  • If patching is not immediately possible, follow the vendor and CISA BOD 22-01 guidance, including discontinuing or isolating the WSUS role where mitigations are unavailable.
  • Restrict network access to WSUS ports (8530/8531) to only required management and client hosts.
  • Review WSUS server exposure and remove internet-facing or unnecessary instances.
  • Monitor for post-exploitation changes to WSUS configuration, approvals and update content.

Detection

  • Hunt for unexpected processes or child processes spawned by the WSUS service (w3wp.exe or wsusservice.exe).
  • Monitor WSUS server logs and IIS logs for anomalous requests to the WSUS API endpoints.
  • Alert on unexpected outbound connections or new services/accounts on WSUS hosts.
  • Audit WSUS update approvals and content changes for tampering.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-59287 to the Known Exploited Vulnerabilities catalog on 24 October 2025 as "Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 14 November 2025.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59287 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1350Windows DNS Server improper input validation remote code executionWindows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication …KEVEPSS 97%analysed9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed9.0CVE-2020-1040Microsoft Hyper-V RemoteFX vGPU input validation remote code executionHyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, allowing remote code …KEVEPSS 7.4%analysed8.8CVE-2026-21510Windows Shell protection mechanism failure allows security feature bypassWindows Shell contains a protection mechanism failure (CWE-693) that lets an unauthorized attacker bypass a security feature over a network. The flaw…KEVEPSS 24%analysed8.8CVE-2026-21513Microsoft MSHTML security feature bypass on WindowsCVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that lets an unauthorized attacker bypass a security fea…KEVEPSS 16%analysed8.8CVE-2025-33073Windows SMB improper access control allows privilege elevationWindows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates …KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2025-59287), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.