Critical Windows Server Vulnerability Fixed with Out-of-Band Update
Microsoft has released an emergency out-of-band update to address a critical remote code execution (RCE) vulnerability in Windows Server Update Services (WSUS). This flaw, tracked as CVE-2025-59287, poses a significant threat to organizations that rely on WSUS for managing updates across enterprise networks. The vulnerability stems from improper handling of update metadata or insecure WSUS configurations, which could allow remote attackers to inject malicious content into the update process. Microsoft has rolled out fixes for various Windows Server versions, including Windows Server 2025, Windows Server 23H2, Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012 R2, and Windows Server 2012. Administrators are urged to apply these patches immediately and review WSUS configurations to ensure secure deployment practices.
Key Takeaways:
- The CVE-2025-59287 vulnerability allows remote, unauthenticated attackers to inject malicious content into the update process, potentially granting them full control of the affected server.
- The vulnerability affects Windows Server versions including Windows Server 2025, Windows Server 23H2, Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012 R2, and Windows Server 2012.
- Temporary workarounds include disabling the WSUS Server Role or blocking inbound traffic to ports 8530 and 8531 via the firewall, but these methods block WSUS functionality and expose systems to other risks.
- Microsoft has temporarily disabled WSUS sync error details in the latest updates as part of its ongoing mitigation efforts for the CVE-2025-59287 vulnerability.
- WSUS has been marked as deprecated in Windows Server, and Microsoft encourages IT administrators to move away from WSUS and adopt modern, cloud-based solutions like Microsoft Intune.
- Microsoft has bundled fixes for the vulnerability into emergency updates for various Windows Server versions.
Statistics:
- The CVE-2025-59287 vulnerability is rated as critical and allows remote, unauthenticated attackers to inject malicious content into the update process.
- Microsoft has released emergency updates to address the issue on various Windows Server versions, including Windows Server 2025, Windows Server 23H2, Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012 R2, and Windows Server 2012.
- Vulnerable systems include Windows Server 2025, Windows Server 23H2, Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012 R2, and Windows Server 2012.
- Microsoft recommends applying patches immediately and reviewing WSUS configurations to ensure secure deployment practices.
Sources:
- Microsoft
- Global Data Point
- SyndiGate Media Inc.