Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability
Microsoft has issued an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting Windows Server Update Services (WSUS).
Microsoft has issued an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting Windows Server Update Services (WSUS).
Identified as CVE-2025-59287 , the vulnerability is due to the deserialization of untrusted data in a legacy serialization mechanism. This flaw allows unauthorized attackers to execute arbitrary code over the network.
The patch was released on Tue, Oct 23, 2025, addressing the critical threat shortly after the vulnerability was initially disclosed on Oct 14, 2025.
The flaw, rated critical with a CVSS 3.1 base score of 9.8, requires no user privileges or interaction, making it highly exploitable via the network with low complexity.
Attackers could exploit this by sending crafted events that trigger unsafe deserialization, potentially leading to full system compromise and significant impacts on confidentiality, integrity, and availability.
While WSUS is not enabled by default on Windows servers, thereby sparing unmodified systems, organizations utilizing the server role for update management face immediate risk if the patch is not applied.
Microsoft's security team updated the CVE's temporal score to 8.8 after confirming the availability of proof-of-concept (PoC) exploit code, increasing the exploitability assessment to "more likely."
No active exploitation has been reported, but the public disclosure of PoC code emphasizes the urgency for administrators to act.
Microsoft has issued an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting Windows Server Update Services (WSUS).
The vulnerability was responsibly reported by researchers from MEOW and CODE WHITE GmbH. Markus Wulftange, among the researchers, identified the deserialization weakness associated with CWE-502.
The update, available through Windows Update, Microsoft Update, and the Microsoft Update Catalog, will sync automatically with WSUS environments. Installation requires a server reboot, potentially disrupting operations in production settings.
For those unable to patch immediately, Microsoft recommends temporary workarounds: disable the WSUS server role entirely, halting client updates, or block inbound traffic to ports 8530 and 8531 at the host firewall level to neutralize the service.
This release underscores ongoing challenges in legacy components like WSUS, which many enterprises still rely on for centralized patch management. Security experts advise organizations to review their WSUS configurations and prioritize the update to prevent potential breaches.
An updated Windows Update offline scan file (Wsusscn2.cab) is now available to aid detection. As cybersecurity threats evolve, this incident highlights the importance of timely patching in enterprise environments. Microsoft continues to monitor for any emerging exploits.
Affected Version Patch KB Number Notes
Windows Server 2012 KB5070887 Standard and Server Core
Windows Server 2012 R2 KB5070886 Standard and Server Core
Windows Server 2016 KB5070882 Standard and Server Core
Windows Server 2019 KB5070883 Standard and Server Core
Windows Server 2022 KB5070884 Standard and Server Core
Windows Server 2022, 23H2 Edition KB5070879 Server Core installation
Windows Server 2025 KB5070881 Standard and Server Core
Based on reporting by Cyber Security News.
