ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Actively Exploited WSUS Bug Added to CISA KEV List

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-59287

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59287
Deserialization RCE in Microsoft WSUS (Windows Server)

CVE-2025-59287 is a deserialization of untrusted data flaw (CWE-502) in the Microsoft Windows Server Update Service (WSUS) that permits remote code execution. It is triggered when the WSUS service processes attacker-controlled serialized input, allowing an attacker to run arbitrary code on the server hosting the WSUS role. Organizations running WSUS are affected — typically enterprises that use the role for internal Windows update management — and CISA lists the affected scope as Microsoft Windows broadly. The issue is confirmed exploited in the wild: it was added to the CISA KEV catalog on 2025-10-24, and the EPSS model assigns a 100% (100th percentile) probability of exploitation within 30 days, though no public proof-of-concept is known. CVSS scoring is not yet available, so defenders should treat it as a high-priority remote code execution issue until more detail is published.

Do: Apply Microsoft's latest WSUS security updates on every Windows Server with the WSUS role enabled and verify patch status through your update and configuration-management tooling. Where the WSUS role is not required, disable or remove it, and restrict inbound network access to WSUS service ports (typically TCP 8530/8531) from untrusted networks. Federal agencies must apply the required mitigations per CISA BOD 22-01 given the KEV listing.

9.8100% KEV PoC
  • Microsoft Windows (systems with the WSUS / Windows Server Update Service role enabled)
largetens of thousands of internet-exposed WSUS servers, within a global deployment base plausibly exceeding 100,000
Full article331 words · extracted from infosecurity-magazine.com · click to collapse

Network defenders have been encouraged to patch a new critical vulnerability in Windows Server Update Services (WSUS) which is being actively exploited.

Microsoft issued an out-of-band update to fix the bug last Thursday, the same day that Huntress observed threat actors targeting WSUS instances publicly exposed on default ports 8530 and 8531.

CVE-2025-59287 is described as a WSUS “deserialization of untrusted data vulnerability” which allows for remote code execution (RCE).

“The vulnerability allows an unauthenticated attacker to achieve remote code execution with system privileges by sending malicious encrypted cookies to the GetCookie() endpoint,” explained security vendor HawkTrace.

The bug reportedly requires no user interaction or privileges to exploit to this end.

Read more on emergency Microsoft patches: Microsoft Issues Out-of-Band Update to Fix Recovery Issues

The US Cybersecurity and Infrastructure Security Agency (CISA) added the CVE to its Known Exploited Vulnerabilities (KEV) catalog on Friday, warning that it poses “significant risks to the federal enterprise.” Agencies have until November 14 to patch.

Widespread Compromise Possible

Although not enabled by default, WSUS is a popular tool that enables IT administrators to centrally manage and distribute Microsoft product updates to networked computers.

Patrick Münch, CISO at Mondoo, said this makes the new vulnerability particularly dangerous.

“A compromised WSUS server could potentially be used to distribute malicious updates to the entire network of client computers, making the flaw particularly high stakes for large enterprises,” he explained.

“Added to that it enables unauthenticated remote code execution and is actively being exploited. This means that organizations should make it a critical priority to immediately mitigate and fix the vulnerability.”

Huntress advised prompt patching for Windows Server customers, but said that organizations could also remediate by isolating network access to WSUS.

“Ensure that only the management hosts and Microsoft Update servers that are explicitly required have access to your WSUS infrastructure,” it said.

“For all other connections, it is strongly recommended that inbound traffic be blocked to TCP ports 8530 and 8531.”

Image credit: Shaheerrr / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/actively-exploited-wsus-bug-cisa/