Microsoft has released an out-of-band update to patch a critical vulnerability in Windows Server Update Services (WSUS). The update addresses CVE-2025-59287">CVE-2025-59287, a remote code execution flaw affecting Windows Server versions 2012 through 2025. The vulnerability stems from insecure deserialization of untrusted data, allowing unauthenticated attackers to execute arbitrary code. A proof-of-concept exploit is publicly available. The vulnerability has been assigned a maximum severity level of "critical". Only servers with the WSUS role enabled are affected. Microsoft recommends admins unable to immediately patch should disable the role on affected servers - although this will obviously prevent client updates from the server. Or they can choose to block inbound traffic to ports 8530 and 8531 on the host firewall to stop WSUS working. The update is cumulative and includes October's patches if not yet installed. A reboot is required. Windows is chock-full of legacy code waiting to be abused by attackers, however, anything that could result in remote code execution requires swift resolution or mitigation. This particular issue relates to a "legacy serialization mechanism," according to Microsoft. WSUS is on the deprecated list for Windows Server, which means it is no longer being actively developed but remains a supported part of the operating system. Microsoft recently confirmed it would continue supporting driver update synchronization to WSUS following user outcry over ...
Microsoft drops surprise Windows Server patch before weekend downtime
The Register
·Richard Speed
·Published Oct 24, 2025
·Updated
Affected Software
2 affected components
Microsoft Windows Server Update Services=2012
Microsoft Windows Server Update Services=2025
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a surprise out-of-band patch released by Microsoft for a critical vulnerability in Windows Server Update Services.
2
What security implications are discussed?
The article highlights a remote code execution flaw, identified as CVE-2025-59287, which could allow attackers to execute harmful code on affected systems.
3
What products or software are affected?
The affected software includes Microsoft Windows Server Update Services, specifically versions 2012 and 2025.
4
What prompted the release of this patch?
The patch was released in response to the discovery of a critical security flaw that posed significant risks to Windows Server users.
5
When was the patch released?
The patch was released just before a planned weekend downtime, indicating urgency in addressing the vulnerability.