CVE-2025-59287CRITICAL 9.8CISA KEVEPSS p100.0%

CVE-2025-59287Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

Microsoft / Windows

Description

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.96% probability of exploitation · percentile 100.0% · 2026-06-15T12:03:41Z
Published2025-10-14
Last modified2025-11-12

CISA KEV entry

Added to KEV: 2025-10-24

Underlying weaknesses· 1

CWE-502

References

  1. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287
  2. https://hawktrace.com/blog/CVE-2025-59287
  3. https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windows-server-wsus-flaw-exploited-in-attacks/
  4. https://www.vicarius.io/vsociety/posts/cve-2025-59287-detection-script-rce-vulnerability-in-windows-server-update-service
  5. https://www.vicarius.io/vsociety/posts/cve-2025-59287-mitigation-script-rce-vulnerability-in-windows-server-update-service
  6. https://gist.github.com/hawktrace/880b54fb9c07ddb028baaae401bd3951
  7. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59287

1

TypeTargetConfidenceTier
WeaknessDeserialization of Untrusted Datacwe-5020%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryMicrosoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerabilitykev-cve-2025-592870%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-20856
CVE
CVE-2025-59237
CVE
CVE-2025-54897
CVE
CVE-2023-21529
CVE
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE
Microsoft SharePoint Deserialization Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.