CVE-2025-59287 – Deserialization RCE in Windows Server Update Services (WSUS)
A critical remote code execution vulnerability (CVE-2025-59287) affects Microsoft Windows Server Update Services (WSUS). The flaw arises from deserialization of untrusted data, allowing an unauthenticated attacker with network access to send crafted serialized payloads and execute arbitrary code with SYSTEM privileges.
Microsoft rated the issue Critical (CVSS 9.8) and released out-of-band security updates on October 24, 2025, covering all supported Windows Server versions. Systems without the WSUS Server Role enabled are not affected. If patching is delayed, administrators can temporarily disable the WSUS role or block inbound traffic on ports 8530/8531 until updates are applied.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. We will update as soon as we have a list of potentially affected assets / confirmed findings.
References:
