{"id":8707,"date":"2025-11-25T10:03:53","date_gmt":"2025-11-25T10:03:53","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/25\/microsofts-update-health-tools-configuration-vulnerability-let-attackers-execute-arbitrary-code-remotely\/"},"modified":"2025-11-25T10:03:53","modified_gmt":"2025-11-25T10:03:53","slug":"microsofts-update-health-tools-configuration-vulnerability-let-attackers-execute-arbitrary-code-remotely","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/25\/microsofts-update-health-tools-configuration-vulnerability-let-attackers-execute-arbitrary-code-remotely\/","title":{"rendered":"Microsoft\u2019s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely"},"content":{"rendered":"<p>    Microsoft\u2019s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical\u00a0remote code execution (<a href=\"https:\/\/cybersecuritynews.com\/oracles-identity-manager-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">RCE<\/a>) vulnerability\u00a0in Microsoft\u2019s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security updates through Intune.<\/p>\n<p>The flaw stems from the tool connecting to dropped <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-attacking-azure-blob-storage\/\" target=\"_blank\" rel=\"noreferrer noopener\">Azure Blob storage<\/a> accounts that attackers could register and control.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-the-vulnerability-works\"><strong>How the Vulnerability Works<\/strong><\/h2>\n<p>The vulnerability exists in version 1.0 of the Update Health Tools, which uses Azure Blob storage accounts following a\u00a0predictable naming pattern\u00a0(payloadprod0 through payloadprod15.blob.core.windows.net) to fetch <a href=\"https:\/\/cybersecuritynews.com\/ibm-qradar-vulnerabilities-let-attackers\/\" target=\"_blank\" rel=\"noreferrer noopener\">configuration files<\/a> and commands.<\/p>\n<p>Eye Security researchers found that Microsoft had left 10 of the 15 storage accounts unregistered and unused.<\/p>\n<p>After registering these abandoned endpoints, the researchers observed over\u00a0544,000 HTTP requests\u00a0within seven days from nearly 10,000 unique Azure tenants worldwide.<\/p>\n<p>The tool\u2019s\u00a0uhssvc.exe\u00a0service, located at C:Program FilesMicrosoft Update Health Tools, was actively resolving these domains across multiple enterprise environments.\u200b<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhICPO4Qcu0DjbOv3glbt_zWAVuFgVU5wC5uA8Oc-OHSlyerIR1sJEW8VipqJLO6ZQ0fgUYHKa6yOQD6riDxZL-n-NQtF1ICWKuDKfa4GoEwgLT-GIMy5a5QRZIJsJFa6crAUY3howIbf3YEZlAWmvhVKmrYQJ3mqAE5Zw9xuR7FmQDpFFaLFxo35lQXTw\/s1600\/Screenshot%25202025-11-25%2520120858%2520%25281%2529.webp?ssl=1\" alt=\"uhssvc.exe file\"><figcaption class=\"wp-element-caption\">uhssvc.exe file<\/figcaption><\/figure>\n<p>The critical issue lies in the tool\u2019s \u201cExecuteTool\u201d action, which allows execution of <a href=\"https:\/\/cybersecuritynews.com\/microsoft-investigation-copilot-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft<\/a>-signed binaries.<\/p>\n<p>By crafting malicious <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leverage-json-storage-services\/\">JSON<\/a> payloads that point to legitimate Windows executables such as explorer.exe, attackers can achieve <a href=\"https:\/\/cybersecuritynews.com\/7-zip-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">arbitrary code <\/a>execution on vulnerable systems.\u200b<\/p>\n<p>The newer version 1.1 implements a proper web service at devicelistenerprod.microsoft.com, though backward-compatibility options could still expose systems.\u200b<\/p>\n<p>Eye Security <a href=\"https:\/\/research.eye.security\/rce-windows-update-health-tools\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> the vulnerability to Microsoft on\u00a0July 7, 2025, and Microsoft confirmed the behavior on July 17.<\/p>\n<p>Hashicorp researchers transferred ownership of all compromised storage accounts back to Microsoft on\u00a0July 18, 2025, effectively closing the attack vector.\u200b<\/p>\n<p>Organizations should ensure they are running the latest version of Update Health Tools and verify no legacy configurations remain enabled.<\/p>\n<p>Security teams should monitor for unusual network traffic to Azure Blob storage endpoints from update services.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsofts-update-health-tools-vulnerability\/\">Microsoft\u2019s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsofts-update-health-tools-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft\u2019s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely A critical\u00a0remote code execution (RCE) vulnerability\u00a0in Microsoft\u2019s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security updates through Intune. The flaw stems from the tool connecting to dropped Azure Blob storage accounts that attackers could register and control.\u200b How [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,158,131,648],"tags":[130],"class_list":["post-8707","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-microsoft","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8707"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8707"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8707\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}