Microsoft Windows Server Update Services (WSUS) is affected by CVE-2025-59287, a critical unauthenticated remote code execution flaw with a CVSS 9.8 score that is being actively exploited in the wild. The vulnerability stems from insecure deserialization of AuthorizationCookie objects handled by the GetCookie() endpoint, allowing a remote attacker to send crafted POST requests to WSUS servers exposed on ports 8530 and 8531 and execute arbitrary code as SYSTEM.
Observed exploitation has involved WSUS-related processes such as w3wp.exe and wsusservice.exe spawning cmd.exe and powershell.exe, indicating full server compromise through the update management service. Microsoft has issued an emergency security update for affected WSUS deployments, while defenders have been urged to patch immediately, restart servers after applying fixes, and restrict inbound access to ports 8530 and 8531 or disable WSUS temporarily if patching cannot be completed at once.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published an alert describing CVE-2025-59287 as a critical actively exploited WSUS vulnerability with CVSS 9.8, caused by insecure deserialization in AuthorizationCookie objects handled by the GetCookie() endpoint. The advisory also recommended restricting inbound traffic to ports 8530 and 8531 or disabling WSUS if patching was not possible.
Attackers were observed actively exploiting exposed Windows Server Update Services servers by sending crafted POST requests to ports 8530 and 8531. Observed abuse included w3wp.exe and wsusservice.exe launching cmd.exe and powershell.exe, indicating code execution as SYSTEM.
Microsoft released an emergency update for the critical WSUS remote code execution vulnerability CVE-2025-59287 and advised administrators to patch affected servers and restart them.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcehawktrace.com
Open sourcehuntress.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.