CyberzSOC

Publication detail
← Back to advisories & guidance

Microsoft Releases Out-of-Band Security Update to Mitigate Windows Server Update Service Vulnerability, CVE-2025-59287 ↗ source

October 24, 2025 CISA Alert

Summary

Updated October 29, 2025 : CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE-2025-59287 , that a prior update did not fully mitigate. CISA strongly urges organizations to implement Microsoft’s updated Windows Server Update Service (WSUS) Remote Code Execution Vulnerability guidance, 1 or risk an unauthenticated actor achieving remote code execution with SYSTEM-level privileges. Immediate actions for organizations with affected products are: Identify servers vulnerable to exploitation (i.e., affected servers with WSUS Server Role enabled and ports open to TCP 8530/TCP 8531) for priority mitigation: Run the following command in PowerShell to check if WSUS is in an installed state: Get-WindowsFeature -Name UpdateServices ; and/or Leverage the Server Manager Dashboard, and check if WSUS enablement is turned on as a Server Role. Run the following command in PowerShell to check if WSUS is in an installed state: Get-WindowsFeature -Name UpdateServices ; and/or Leverage the Server Manager Dashboard, and check if WSUS enablement is turned on as a Server Role.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-59287 9.8 Critical Microsoft Windows Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.