They Hacked Windows Updates?! Inside the WSUS RCE Exploit CVE-2025-59287

They Hacked Windows Updates?! Inside the WSUS RCE Exploit CVE-2025-59287

Microsoft WSUS , the trusted Windows patching system , has been currently under attack.

CVE-2025-59287 is an unauthenticated remote code execution flaw that allows attackers to send a single crafted cookie and get SYSTEM-level control over WSUS servers.

Once compromised, adversaries can distribute malicious updates to every connected endpoint.

Microsoft has released an out-of-band patch (Oct 23, 2025), but exploitation is already in the wild and CISA added it to KEV.

In my latest video, I unpack:

  • The technical root cause (unsafe .NET deserialization)

  • The exploitation timeline

  • Active threat actor behavior

  • Practical detection and hardening steps

Watch the breakdown here and a full article from here

What’s your org doing to isolate or monitor WSUS after this? Curious to hear mitigation approaches from fellow defenders.

0 comments

Leave a comment

Our Best Pick of Cyber Security Notes

Cyber Security Certification Notes
The Unofficial Offensive Security AI Red Teamer Study Notes + FREE Cheat Sheet

Cyber Security Certification Notes

Cyber Security Study Guides
The Kali Linux Pentesting Cheat Sheet

Cyber Security Study Guides

AI & ML Study Guides
Master AI for Content Creation, Business & Marketing

AI & ML Study Guides

IT Study Guides
The Definitive Networking Cheat Sheet (Tools)

IT Study Guides