CVE-2025-59287: Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
— CISA
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22826Patch KB5070886 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25728Patch KB5070887 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8524Patch KB5070882 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.6905Patch KB5070893 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4297Patch KB5070892 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1916Patch KB5070879 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.7922Patch KB5070883
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59287?
CVE-2025-59287 is classified as a critical Remote Code Execution vulnerability.
How do I fix CVE-2025-59287?
The recommended fix for CVE-2025-59287 is to apply the latest security patches provided by Microsoft for affected Windows Server versions.
Which Windows Server versions are affected by CVE-2025-59287?
CVE-2025-59287 affects multiple Windows Server versions including 2012, 2016, 2019, 2022, and 2025.
What are the potential impacts of CVE-2025-59287?
Exploiting CVE-2025-59287 can allow an unauthorized attacker to execute arbitrary code on affected systems.
Is there a user-friendly way to identify if my system is impacted by CVE-2025-59287?
Users can check their system's update history to see if they have installed the necessary security updates addressing CVE-2025-59287.