Vulnerability Description
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows Server 2012 | - |
| Microsoft | Windows Server 2016 | < 10.0.14393.8524 |
| Microsoft | Windows Server 2019 | < 10.0.17763.7922 |
| Microsoft | Windows Server 2022 | < 10.0.20348.4297 |
| Microsoft | Windows Server 2022 23H2 | < 10.0.25398.1916 |
| Microsoft | Windows Server 2025 | < 10.0.26100.6905 |
Related Weaknesses (CWE)
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287Vendor Advisory
- https://hawktrace.com/blog/CVE-2025-59287ExploitThird Party Advisory
- https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windowsPress/Media Coverage
- https://www.vicarius.io/vsociety/posts/cve-2025-59287-detection-script-rce-vulneThird Party Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-59287-mitigation-script-rce-vulnMitigationThird Party Advisory
- https://gist.github.com/hawktrace/880b54fb9c07ddb028baaae401bd3951Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2025-59287?
CVE-2025-59287 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
How severe is CVE-2025-59287?
CVE-2025-59287 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-59287?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows Server 2012, Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Windows Server 2022 23H2.