Microsoft has released emergency out-of-band security updates to address a critical remote code execution (RCE) vulnerability in Windows Server Update Services (WSUS), tracked as CVE-2025-59287. The flaw, rated CVSS 9.8, allows unauthenticated attackers to exploit unsafe deserialization in the WSUS AuthorizationCookie mechanism, enabling arbitrary code execution with SYSTEM privileges. Proof-of-concept exploit code for this vulnerability is publicly available, increasing the urgency for organizations to patch affected systems immediately. The vulnerability affects only Windows servers with the WSUS Server Role enabled, and Microsoft has provided security updates for all supported Windows Server versions, along with workarounds for those unable to patch immediately.
Security researcher Batuhan Er from HawkTrace detailed that the vulnerability arises from the unsafe deserialization of AuthorizationCookie objects sent to the GetCookie() endpoint, where encrypted cookie data is decrypted and deserialized without proper type validation. This flaw exposes WSUS servers to remote, unauthenticated attacks that require no user interaction and could potentially be wormable between WSUS servers. Microsoft strongly advises administrators to install the provided patches or apply recommended mitigations to prevent exploitation of this critical vulnerability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
A Metasploit Framework pull request published an exploit module for the unauthenticated WSUS deserialization flaw, further lowering the barrier to weaponization and testing.
Microsoft disclosed that the patch released for CVE-2025-59287 had the side effect of disabling Windows Server hotpatching, creating an operational issue for some customers after applying the fix.
On November 3, reporting said exploitation had affected at least 50 organizations, with Google's Threat Intelligence Group attributing related activity to a newly tracked threat cluster, UNC6512. Eye Security also said two additional threat actors had conducted intrusions against vulnerable WSUS instances.
By early November, defenders reported notable scanning activity against TCP ports 8530 and 8531, likely tied to efforts to find vulnerable WSUS servers for CVE-2025-59287 exploitation.
Reporting on October 30 indicated that some CVE-2025-59287 exploitation activity was being used to deploy the Skuld infostealer, showing post-exploitation monetization beyond reconnaissance.
Security researchers and government advisories warned that thousands of WSUS instances were reachable from the internet, raising concern that compromise of a WSUS server could enable broader internal supply-chain style attacks.
By late October, Google threat researchers were probing exploitation of CVE-2025-59287 as warnings mounted about attacks against exposed WSUS infrastructure.
CISA issued a warning directing U.S. federal civilian agencies to remediate the exploited WSUS vulnerability, advising identification of exposed servers, application of Microsoft's update, and use of mitigations if patching could not be completed immediately.
CISA added CVE-2025-59287 to its Known Exploited Vulnerabilities catalog after reports of in-the-wild exploitation, elevating urgency for remediation across affected organizations.
The Netherlands' NCSC said it learned from a trusted partner that exploitation of the WSUS flaw had been observed on October 24, warning that public exploit availability increased the risk to exposed servers.
On October 24, Eye Security reported scanning and exploitation attempts targeting CVE-2025-59287, including at least one customer compromise using an exploit different from the public proof of concept.
Security firms including Huntress reported attacks beginning on October 23 against internet-exposed WSUS instances, with attackers sending crafted requests, spawning cmd.exe and PowerShell, performing reconnaissance, and exfiltrating results to attacker-controlled infrastructure.
On October 23, Microsoft issued an emergency out-of-band update for CVE-2025-59287, a critical unauthenticated WSUS remote code execution bug affecting Windows Server systems with the WSUS role enabled. Microsoft also recommended rebooting after patching and suggested disabling WSUS or blocking ports 8530/8531 as temporary mitigations.
Researchers published technical details and proof-of-concept exploit code for CVE-2025-59287, describing unsafe deserialization of WSUS AuthorizationCookie objects and making exploitation easier for attackers.
Microsoft initially addressed CVE-2025-59287 in its October 2025 Patch Tuesday updates, but later acknowledged that this first fix did not fully mitigate the WSUS remote code execution flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
38 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceunit42.paloaltonetworks.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.