Microsoft on Thursday released out-of-band security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with a proof-of-concept (Poc) exploit publicly available and has come under active exploitation in the wild.
The vulnerability in question is CVE-2025-59287 (CVSS score: 9.8), a remote code execution flaw in WSUS that was originally fixed by the tech giant as part of its Patch Tuesday update published last week.
Three security researchers, MEOW, f7d8c52bec79e42795cf15888b85cbad, and Markus Wulftange with CODE WHITE GmbH, have been acknowledged for discovering and reporting the bug.
The shortcoming concerns a case of deserialization of untrusted data in WSUS that allows an unauthorized attacker to execute code over a network. It's worth noting

 The Hacker News
 The Hacker News

 The Register
 The Register Android Central
 Android Central The Columbian Business
 The Columbian Business CNN Business
 CNN Business Cinema Blend
 Cinema Blend The Columbian Life
 The Columbian Life The Daily Beast
 The Daily Beast WFMJ-TV Entertainment
 WFMJ-TV Entertainment