Critical Exploit in WSUS Enables Remote Code Execution

20 Oct 2025

A proof-of-concept exploit has emerged for a critical vulnerability in Microsoft Windows Server Update Services (WSUS), potentially enabling remote code execution with SYSTEM privileges. The vulnerability is designated CVE-2025-59287, affecting Windows Server versions from 2012 to 2025, and has been assigned a CVSS v3.1 score of 9.8.

Vulnerability Details and Risks

The flaw arises from unsafe deserialization of data in WSUS's AuthorizationCookie handling, specifically within the GetCookie() endpoint. The issue enables crafted payloads to execute arbitrary code due to inadequate validation during cookie processing. The vulnerability is exploited via a SOAP envelope request with a tampered AuthorizationCookie, leveraging AES-128-CBC encryption.

Microsoft has classified the vulnerability as "Exploitation More Likely," highlighting the risk across networked WSUS servers. The company warns of the potential for "wormable" exploits due to the vulnerability's nature.

Mitigation and Recommendations

Microsoft's October 2025 Patch Tuesday includes crucial patches addressing this flaw. Organizations are urged to apply these updates without delay, isolate WSUS servers, and implement stringent firewall rules. Additionally, transitioning from BinaryFormatter to safer serializers like JSON or XML with strict validation is recommended.

The appearance of a public PoC by researcher hawktrace on GitHub demonstrates potential command execution, emphasizing the urgency of protective measures. While no active exploitation is yet reported, the available PoC signals elevated risk.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6168755
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1178745
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
449576
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
449269
downloads

News and reviews for Desktop Windows

MindsEye Sparks Turmoil at Build a Rocket Boy

MindsEye's launch leads to layoffs and allegations of mismanagement at Build a Rocket Boy. Former employees point to leadership issues.

Read more

Escape From Duckov Sells 500,000 Copies, Gains Popularity

Escape From Duckov by Team Soda sold 500,000 copies in the first weekend, offering an accessible take on extraction shooters.

Read more

DefenderWrite Exploits Antivirus Whitelisting on Windows

DefenderWrite uses DLL injection to exploit Windows AV whitelisting, challenging antivirus vendors.

Read more

Critical Exploit in WSUS Enables Remote Code Execution

A new vulnerability in WSUS allows attackers remote code execution. Organizations should patch immediately to avoid potential threats.

Read more

Secure Expedition 33 on Fanatical for Just $1

Expedition 33's unique blend of combat mechanics is available on Fanatical for as low as $1, expanding player choices in the RPG genre.

Read more

DOSBox Pure Unleashed Launches on Windows, Mac, Linux

Psyraven releases DOSBox Pure Unleashed, an emulator for Windows, macOS, Linux. Features Windows 9X support, 3dfx graphics, MIDI playback.

Read more

Mina Hollower Adds Retro Mechanics, Ditches Parry

Mina Hollower by Yacht Club Games rejects parry mechanics for retro influences, blending elements from Castlevania and Bloodborne.

Read more

Motion Twin Chooses Windblown Over Dead Cells Sequel

Motion Twin focuses on Windblown, a new co-op game, over a Dead Cells sequel. Developer prioritizes creativity over business pressure.

Read more

Windows 10 Gets Extended Security Until 2026

Microsoft offers Windows 10 Extended Security Updates (ESU) until 2026 for users delaying upgrading to Windows 11.

Read more

Windows 11 25H2 Update: Stability with Extended Support

Windows 11 25H2, released worldwide, streamlines updates by removing legacy features, extending support until 2027.

Read more