HomeSecurityPoC exploit released for Windows Server Update Services vulnerability

PoC exploit released for Windows Server Update Services vulnerability

A proof-of-concept (PoC) exploit has been released for a critical vulnerability in Microsoft's Windows Server Update Services (WSUS) . The vulnerability allows unauthenticated remote attackers to execute code with SYSTEM privileges on affected servers. The vulnerability is tracked as CVE-2025-59287 and carries a CVSS score of 9.8/10, highlighting the high risk to enterprise infrastructure.

Windows Server Update Services

WSUS is a server role in Windows Server that helps IT administrators deploy Microsoft updates across networks, ensuring that systems stay up-to-date and secure.

See also: ConnectWise: New serious vulnerabilities in the Automate platform

The bug results from “unsafe deserialization of untrusted data” when handling AuthorizationCookie in WSUS. Specifically, the EncryptionHelper.DecryptData() decrypts cookie data (AES-128-CBC) and passes it to .NET’s BinaryFormatter for deserialization—an older serializer without type restrictions. This allows the creation of malicious payloads that execute arbitrary code, with the final execution occurring in the SYSTEM context.

Windows Server Update Services – Vulnerability: Who is exposed

All supported Windows Server versions from 2012 to 2025, as the GetCookie() endpoint processes encrypted AuthorizationCookie objects without sufficient validation. WSUS has been deprecated due to new features, but is still widely used in production environments and receives ongoing security support.

Attack flow and PoC

PoC exploit released for Windows Server Update Services vulnerability

The exploit starts with an unauthorized HTTP POST request to the WSUS ClientWebService endpoint on port 8530.The attackers send a SOAP envelope with a forged AuthorizationCookie that has a PlugInId of “SimpleTargeting” and encrypted payload data. The server decrypts the cookie using a hardcoded key (“877C14E433638145AD21BD0C17393071”), removes the IV block, and deserializes the result via BinaryFormatter.

See also: Pwn2Own Automotive 2026: Over $3 million in prizes to be awarded

A public PoC on GitHub, shared by researcher “hawktrace,” demonstrates payload creation in C# (learn more here). No user interaction is required, making it extremely dangerous for exposed WSUS instances.

Supply chain risks

The most worrying prospect is the risk of supply chain attacks: a compromised WSUS server could distribute modified or malicious updates to clients, causing widespread breaches in organizations. Although no exploits have been reported yet, public access to PoC dramatically increases the likelihood of malicious attacks.

PoC exploit released for Windows Server Update Services vulnerability

Recommended measures

Microsoft says the vulnerability was discovered by researcher “MEOW” and urges organizations to immediately apply the security updates October 2025 via Windows Update or WSUS. Additionally, it recommends isolating WSUS servers, restricting access through firewalls, monitoring for anomalous SOAP traffic, and looking for abnormal POST requests.

See also: WatchGuard vulnerability allows malicious code execution

To prevent similar vulnerabilities, Microsoft recommends removing BinaryFormatter and switching to safer serializers (JSON/XML) with strict checks and validation.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS