Security researchers warn that a vulnerability in Windows Server Update Services (WSUS) is being actively exploited by Chinese state-sponsored threat actors to spread malware globally. This vulnerability, identified as CVE-2025-59287, has a severity score of 9.8/10 and allows remote code execution without user interaction.

CVE-2025-59287 Details

The flaw is a deserialization-of-untrusted-data bug that permits attackers to execute code with SYSTEM privileges. Microsoft addressed the vulnerability in its October 2025 Patch Tuesday update following a public proof-of-concept release.

  • The vulnerability was given a 9.8 severity score.
  • Allows unauthenticated remote code execution.
  • Patch released in October 2025 by Microsoft.

Attack Methods and Targets

AhnLab Security Intelligence Center revealed that attackers use PowerCat, an open-source PowerShell utility, to gain system shell access on unpatched WSUS servers. They subsequently download and install ShadowPad, a modular backdoor, leveraging tools like certutil and curl.

ShadowPad is deployed via DLL side-loading using a legitimate executable named ETDCtrlHelper.exe. The primary targets include sectors such as government, defense, and telecommunications.

Preventive Measures

The exploitation began after the public release of PoC exploit code, leading to quick weaponization by attackers. Administrators are urged to patch WSUS servers promptly to mitigate this critical vulnerability effectively.

This attack underscores the importance of maintaining updated security measures, especially for critical systems that serve sensitive infrastructure sectors worldwide.

WSUS Offline Update

WSUS Offline Update download for free to PC or mobile

Latest update WSUS Offline Update download for free for Windows PC or Android mobile

4
527 reviews
2420 downloads

News and reviews about WSUS Offline Update

24 Nov 2025

Critical WSUS Vulnerability Exploited for Malware Spread

State-sponsored hackers exploit WSUS flaw; critical sectors at risk globally.

Read more

27 Oct 2025

Microsoft Patches Critical Cybersecurity Vulnerability

Microsoft issues crucial security updates for Windows Server, addressing an active exploitation threat. Stay alert for new cybersecurity risks.

Read more

27 Oct 2025

Microsoft Patches Critical WSUS Vulnerability Quickly

Microsoft releases a second WSUS update to address critical server vulnerabilities affecting multiple Windows versions, following active exploits.

Read more

25 Oct 2025

Microsoft Urges Immediate WSUS Update to Block Remote Attacks

Microsoft issued an urgent WSUS update; CISA confirms immediate threats, impacting global networks.

Read more

24 Oct 2025

Emergency Patch Fixes Critical WSUS Flaw Allowing Exploits

Microsoft releases a Patch for a critical WSUS vulnerability CVE-2025-59287 enabling remote code execution. Immediate update is advised.

Read more

29 Jun 2024

Microsoft to Deprecate WSUS Driver Synchronization Feature in April 2025

Microsoft will deprecate the drive synchronization capability in WSUS on April 18, 2025. With only 34% of WSUS users utilizing driver updates, Microsoft has decided to discontinue the feature.

Read more