• News/
  • https://www.theregister.com/2025/10/24/windows_server_patch/

Microsoft drops surprise Windows Server patch before weekend downtime

The Register
·
Richard Speed
·
Published Oct 24, 2025
·
Updated

Microsoft has released an out-of-band update to patch a critical vulnerability in Windows Server Update Services (WSUS). The update addresses CVE-2025-59287">CVE-2025-59287, a remote code execution flaw affecting Windows Server versions 2012 through 2025. The vulnerability stems from insecure deserialization of untrusted data, allowing unauthenticated attackers to execute arbitrary code. A proof-of-concept exploit is publicly available. The vulnerability has been assigned a maximum severity level of "critical". Only servers with the WSUS role enabled are affected. Microsoft recommends admins unable to immediately patch should disable the role on affected servers - although this will obviously prevent client updates from the server. Or they can choose to block inbound traffic to ports 8530 and 8531 on the host firewall to stop WSUS working. The update is cumulative and includes October's patches if not yet installed. A reboot is required. Windows is chock-full of legacy code waiting to be abused by attackers, however, anything that could result in remote code execution requires swift resolution or mitigation. This particular issue relates to a "legacy serialization mechanism," according to Microsoft. WSUS is on the deprecated list for Windows Server, which means it is no longer being actively developed but remains a supported part of the operating system. Microsoft recently confirmed it would continue supporting driver update synchronization to WSUS following user outcry over ...

Read full article

Affected Software

2 affected components
Microsoft Windows Server Update Services=2012
Microsoft Windows Server Update Services=2025
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a surprise out-of-band patch released by Microsoft for a critical vulnerability in Windows Server Update Services.

2

What security implications are discussed?

The article highlights a remote code execution flaw, identified as CVE-2025-59287, which could allow attackers to execute harmful code on affected systems.

3

What products or software are affected?

The affected software includes Microsoft Windows Server Update Services, specifically versions 2012 and 2025.

4

What prompted the release of this patch?

The patch was released in response to the discovery of a critical security flaw that posed significant risks to Windows Server users.

5

When was the patch released?

The patch was released just before a planned weekend downtime, indicating urgency in addressing the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203