Windows Server Update Service
CVE-2025-59287 — Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
Executive Summary
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Overview
9.8
CVSS CRITICAL
Critical
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 8.8
EPSS Score
0.99938
probability of exploitation in the next 30 days
0.99971 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
9 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows Server 2012 | 5070887 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 (Server Core installation) | 5070887 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 R2 | 5070886 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5070886 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2016 | 5070882 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5070882 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 | 5070883 (Security Update) |
Critical | Remote Code Execution | Maybe |
| Windows Server 2019 (Server Core installation) | 5070883 (Security Update) |
Critical | Remote Code Execution | Maybe |
| Windows Server 2022 5070884 (Security Update) 5070892 (Standalone Security Update) Critical Remote Code Execution Base: 9.8 Temporal: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C 10.0.20348.4297 Yes None Windows Server 2022 (Server Core installation) 5070884 (Security Update) 5070892 (Standalone Security Update) Critical Remote Code Execution Base: 9.8 Temporal: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C 10.0.20348.4297 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5070879 (Security Update) |
Critical | Remote Code Execution | Yes |
Patches
5 patches
| Article | Type | Restart |
|---|---|---|
5070887 |
Security Update | Yes |
5070886 |
Security Update | Yes |
5070882 |
Security Update | Yes |
5070883 |
Security Update | Maybe |
5070879 |
Security Update | Yes |
Exploits & PoC
15 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| jiansiting/CVE-2025-59287 | 175 | 2025-10-25 | WSUS Unauthenticated RCE |
| mubix/Find-WSUS | 46 | 2025-10-27 | Helps defenders find their WSUS configurations in the wake of CVE-2025-59287 |
| Lupovis/Honeypot-for-CVE-2025-59287-WSUS | 26 | 2025-10-27 | Defensive PoC decoy for CVE-2025-59287 (WSUS) - emulates WSUS endpoints, captures request bodies and metadata, saves evidence for forensic analysis, and provides validation harness and detection rules |
| tecxx/CVE-2025-59287-WSUS | 18 | 2025-10-27 | powershell version of hawktrace POC exploit |
| garvitv14/CVE-2025-59287 | 16 | 2025-10-25 | Working exploit (PoC) for CVE-2025-59287 — WSUS vulnerability. Featured on Vulners and DeepWiki. |
| M507/CVE-2025-59287-PoC | 15 | 2025-11-16 | Unauthenticated RCE PoC in Microsoft Windows Server Update Service (WSUS) - CVE-2025-59287 & CVE-2023-35317 |
| QurtiDev/WSUS-CVE-2025-59287-RCE | 11 | 2025-11-01 | Exploit script written in C# to aid gaining a reverse shell on targets with Windows Server Update Service(WSUS) CVE-2025-59287. |
| AdityaBhatt3010/CVE-2025-59287-When-your-patch-server-becomes-the-attack-vector | 10 | 2025-10-28 | CVE-2025-59287 — Critical unauthenticated RCE in Windows Server Update Services (WSUS) via unsafe deserialization of an AuthorizationCookie, enabling SYSTEM-level compromise and active exploitation; p |
| 0x7556/CVE-2025-59287 | 7 | 2025-10-30 | CVE-2025-59287 注入WolfShell内存马 |
| mrk336/Breaking-the-Update-Chain-Inside-CVE-2025-59287-and-the-WSUS-RCE-Threat | 3 | 2025-10-28 | CVE-2025-59287 is a critical RCE vulnerability in Windows Server Update Services (WSUS) caused by unsafe deserialization of untrusted data. It allows remote attackers to execute arbitrary code without |
| LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE | 2 | 2026-01-16 | |
| 0xBruno/WSUSploit.NET | 1 | 2025-10-26 | PoC for CVE-2025-59287 |
| esteban11121/WSUS-RCE-Mitigation-59287 | 1 | 2025-10-28 | Guía de respuesta rápida y script de auditoría para CVE-2025-59287 (RCE crítica en WSUS). |
| fsanzmoya/wsus_CVE-2025-59287 | 1 | 2025-10-29 | Verificacion de vulnerabilidad en WSUS |
| Twodimensionalitylevelcrossing817/CVE-2025-59287 | 1 | 2025-11-15 |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 3
Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
high
Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
high
DNS Query to External Service Interaction Domains
high
Nuclei templates 1
nuclei -id CVE-2025-59287
Acknowledgments
Markus Wulftange
MEOW
f7d8c52bec79e42795cf15888b85cbad
References
On This Page