On the 14th of October 2025, CVE-2025-59287 was published. Three security researchers, MEOW, f7d8c52bec79e42795cf15888b85cbad and Markus Wulftange (Code White GmbH), are credited with discovering the critical vulnerability in the Windows Server Update Service (WSUS). This flaw could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable host.
Technical details
CVE-2025-59287 is an unsafe deserialization vulnerability in the WSUS reporting component. In short, WSUS accepts serialized data from a network request and deserializes it without performing sufficient validation. A specially crafted serialized payload can cause unexpected object instantiation during deserialization, which in turn can be abused to execute code inside the WSUS process.
The vulnerable code path is reachable over the network on hosts that have the WSUS Server Role enabled, so only machines running this role are affected. Exploitation requires no authentication or user interaction and results in code executing in the context of the WSUS service process, which typically runs with system level privileges. Public proof of concept exploit code and active exploitation were observed after Microsoft released an out of band patch on the 23rd of October 2025.
Impact summary
The WSUS vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands as SYSTEM on affected Windows Server hosts by sending a specially crafted WSUS event. Successful exploitation could lead to full compromise of the WSUS host, which in turn could be used to deploy malicious updates to compromise other hosts across a Windows based IT environment.
Mitigating the vulnerability
CVE-2025-59287 has been fully addressed in security updates released on the 23rd of October 2025. Organisations relying on WSUS are strongly advised to apply the relevant following available updates without delay:
- Windows Server 2025 (KB5070881)
- Windows Server, version 23H2 (KB5070879)
- Windows Server 2022 (KB5070884)
- Windows Server 2019 (KB5070883)
- Windows Server 2016 (KB5070882)
- Windows Server 2012 R2 (KB5070886)
- Windows Server 2012 (KB5070887)
If you are unable to apply the latest update immediately, admins can mitigate the issue by temporarily disabling the WSUS server role or by blocking inbound traffic to Ports 8530 and 8531 on the host firewall until the update can be applied. This does however mean clients relying on WSUS for updates will no longer receive updates from the server.
How can Sentrium help?
Sentrium offer vulnerability assessment and network penetration testing services that can support you in identifying vulnerable Windows Server systems across your environments. Start your assessment today by completing our pentest scoping form or get in touch with our team to find out more about our penetration testing services.