Microsoft Patches Critical WSUS Vulnerability Quickly

27 Oct 2025

Microsoft has issued a second update for a critical remote code execution vulnerability in Windows Server Update Services (WSUS). This patch is aimed at fully resolving the security risk after the initial fix proved insufficient, leaving systems vulnerable to active exploitation.

Scope of the Update

The vulnerability, identified as CVE-2025-59287, impacts WSUS on a range of Windows Server versions, including 2012, 2016, 2019, 2022, and 2025. It results from unsafe deserialization of AuthorizationCookie data, allowing unauthenticated individuals to execute remote code at a SYSTEM level.

Reportedly, malicious actors have been exploiting the vulnerability by sending crafted cookies to the GetCookie() endpoint. This severe risk prompted urgent actions from security agencies.

Security Advisories and Mitigations

Multiple security firms, including HawkTrace, Eye Security, and Huntress, confirmed active exploitation of the bug. Eye Security reported roughly 2,500 WSUS servers as exposed globally, while Huntress detected attacks targeting default WSUS ports 8530 and 8531.

Organizations such as CISA and the Dutch NCSC have issued advisories urging immediate application of the update, released out-of-band on 2023-10-23, and a reboot of affected servers. They recommend these actions to mitigate risks while the update is applied:

  • Disable the WSUS Server Role.
  • Block inbound traffic to ports 8530/8531.

These mitigations should remain in place until the update is fully installed to ensure system security.

Conclusion

Administrators are strongly advised to apply the latest WSUS update and follow mitigation steps to secure their systems promptly. Microsoft’s rapid response underscores the need for vigilant application of security patches to prevent unauthorized access and potential damage.

WSUS Offline Update

WSUS Offline Update download for free to PC or mobile

Latest update WSUS Offline Update download for free for Windows PC or Android mobile

4
527 reviews
2418 downloads

News and reviews about WSUS Offline Update

27 Oct 2025

Microsoft Patches Critical Cybersecurity Vulnerability

Microsoft issues crucial security updates for Windows Server, addressing an active exploitation threat. Stay alert for new cybersecurity risks.

Read more

27 Oct 2025

Microsoft Patches Critical WSUS Vulnerability Quickly

Microsoft releases a second WSUS update to address critical server vulnerabilities affecting multiple Windows versions, following active exploits.

Read more

25 Oct 2025

Microsoft Urges Immediate WSUS Update to Block Remote Attacks

Microsoft issued an urgent WSUS update; CISA confirms immediate threats, impacting global networks.

Read more

24 Oct 2025

Emergency Patch Fixes Critical WSUS Flaw Allowing Exploits

Microsoft releases a Patch for a critical WSUS vulnerability CVE-2025-59287 enabling remote code execution. Immediate update is advised.

Read more

29 Jun 2024

Microsoft to Deprecate WSUS Driver Synchronization Feature in April 2025

Microsoft will deprecate the drive synchronization capability in WSUS on April 18, 2025. With only 34% of WSUS users utilizing driver updates, Microsoft has decided to discontinue the feature.

Read more