{"id":7914,"date":"2025-10-24T10:03:28","date_gmt":"2025-10-24T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/24\/microsoft-releases-emergency-patch-for-windows-server-update-service-rce-vulnerability\/"},"modified":"2025-10-24T10:03:28","modified_gmt":"2025-10-24T10:03:28","slug":"microsoft-releases-emergency-patch-for-windows-server-update-service-rce-vulnerability","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/24\/microsoft-releases-emergency-patch-for-windows-server-update-service-rce-vulnerability\/","title":{"rendered":"Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability"},"content":{"rendered":"<p>    Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft has rolled out an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting the Windows Server Update Services (WSUS).<\/p>\n<p>Identified as <a href=\"https:\/\/cybersecuritynews.com\/poc-wsus-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-59287<\/a>, the issue stems from the deserialization of untrusted data in a legacy serialization mechanism, allowing unauthorized attackers to execute arbitrary code over the network.<\/p>\n<p>The patch, released on <a href=\"https:\/\/cybersecuritynews.com\/microsoft-october-2025-patch-tuesday\/\" target=\"_blank\" rel=\"noreferrer noopener\">October 23, 2025<\/a>, addresses the critical threat just days after the vulnerability\u2019s initial disclosure on October 14.<\/p>\n<p>The flaw, rated critical with a CVSS 3.1 base score of 9.8, requires no user privileges or interaction, making it highly exploitable via the network with low complexity. <\/p>\n<p>Attackers could send crafted events to trigger unsafe deserialization, potentially leading to full system compromise and severe impacts on confidentiality, integrity, and availability.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-vulnerability-exposes-wsus-servers-to-remote-attacks\"><strong>Vulnerability Exposes WSUS Servers To Remote Attacks<\/strong><\/h2>\n<p>While WSUS is not enabled by default on Windows servers, thus sparing unmodified systems, organizations running the server role for update management face immediate risk if unpatched.<\/p>\n<p>Microsoft\u2019s security team updated the CVE\u2019s temporal score to 8.8 after confirming the availability of proof-of-concept (PoC) exploit code, elevating the exploitability assessment to \u201cmore likely.\u201d <\/p>\n<p>No active exploitation in the wild has been reported yet, but the public disclosure of <a href=\"https:\/\/cybersecuritynews.com\/poc-wsus-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">PoC code<\/a> underscores the urgency for administrators to act.<\/p>\n<p>The vulnerability was responsibly reported by researchers from MEOW and CODE WHITE GmbH, including Markus Wulftange, who identified the deserialization weakness tied to CWE-502.<\/p>\n<p>The October 23 update is available through Windows Update, Microsoft Update, and the Microsoft Update Catalog for standalone downloads. <\/p>\n<p>It will also sync automatically with WSUS environments. However, installation requires a server reboot, which could disrupt operations in production settings. <\/p>\n<p>For those unable to patch immediately, Microsoft recommends temporary workarounds: disable the WSUS server role entirely, halting client updates in the process, or block inbound traffic to ports 8530 and 8531 at the host firewall level to neutralize the service.<\/p>\n<p>This release highlights ongoing challenges in legacy components like WSUS, which many enterprises still rely on for centralized patch management. <\/p>\n<p>Security experts urge organizations to review their WSUS configurations and prioritize the update to prevent potential breaches. <\/p>\n<p>An updated <a href=\"https:\/\/cybersecuritynews.com\/windows-11-24h2-update-video\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Update<\/a> offline scan file (Wsusscn2.cab) is now available to aid detection. As cybersecurity threats evolve, this incident serves as a reminder of the importance of timely patching in enterprise environments. Microsoft continues to monitor for any emerging exploits.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/wsus-rce-vulnerability\/\">Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/wsus-rce-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability Microsoft has rolled out an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting the Windows Server Update Services (WSUS). Identified as CVE-2025-59287, the issue stems from the deserialization of untrusted data in a legacy serialization mechanism, allowing unauthorized attackers to execute [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-7914","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7914"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7914"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7914\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7914"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7914"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7914"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}