CVE-2025-59287
KEVCRITICAL 9.8EPSS 100.0%
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.98% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-10-24
- Nuclei
- critical · CWE-502
- Published
- 2025-10-14
- Updated
- 2026-02-26
Proof-of-concept exploits (19)
- trustedsec/spoonmap198★ · 2026-08-28
- 0x7556/CVE-2025-59287
- 0xBruno/WSUSploit.NET
- Adel-hx0d/cve-2025-59287
- DaddyBigFish/CVE-2025-59287-hawktrace
- FurkanKAYAPINAR/CVE-2025-59287
- LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE
- Lupovis/Honeypot-for-CVE-2025-59287-WSUS
- M507/CVE-2025-59287-PoC
- MaxymGorn/cve-2025-59287-exploit-poc
- QurtiDev/WSUS-CVE-2025-59287-RCE
- garvitv14/CVE-2025-59287
- jiansiting/CVE-2025-59287
- mubix/Find-WSUS
- ross-ns/WSUS-CVE-2025-59287
- swoon69/CVE-2025-59287-Exercise-Use
- tecxx/CVE-2025-59287-WSUS
- kennedy-aikohi/WSUS-Exploitation-and-Velociraptor-Assisted-LockBit-Ransomware-Attempt
- tijldeneut/Security