CVE-2025-59287
⚡ CISA KEVPublished: —Modified: —Vendor: MicrosoftProduct: Windows
—
CVSS v3
99.9%
EPSS
⚡ Added to KEV on 2025-10-24 · Federal agencies must remediate by 2025-11-14
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
💣 Public Exploits0
From Exploit-DB
No public exploits in Exploit-DB.
🔍 Sigma Detection Rules2
Rules tagged with this CVE
| high | Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process | windows | — |
| high | Exploitation Activity of CVE-2025-59287 - WSUS Deserialization | windows | — |
🛠️ Patch Details11
Affected/fixed versions from threat intel reports
| Microsoft Windows Server | source ↗ | ||
| Microsoft Windows Server Update Services (WSUS) | — | — | source ↗ |
| Microsoft Windows Server Update Services (WSUS) | — | — | source ↗ |
| Microsoft Windows Server 2019 | source ↗ | ||
| Microsoft Windows Server 2022 | source ↗ | ||
| Microsoft Windows Server 2012 | source ↗ | ||
| Microsoft Windows Server Update Services | — | — | source ↗ |
| Microsoft Windows Server 2025 | source ↗ | ||
| Microsoft Windows Server 2012 R2 | source ↗ | ||
| Microsoft Windows Server 2016 | source ↗ | ||
| Microsoft Windows Server Update Services | source ↗ |
📰 Threat Intel Coverage15
Digest reports mentioning this CVE
📎 References0
No reference URLs.