Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

Banner Thumbnail
Attack Overview

CVE-2025-59287: When the patch server becomes the attack vector

Year of occurrence: 2025 (disclosed and CVE issued)

The vulnerability CVE-2025-59287 (WSUS Remote Code Execution)

A critical remote code execution (RCE) flaw in Windows Server Update Services (WSUS), tracked as CVE-2025-59287, allowed attackers to run arbitrary code as SYSTEM, one of the highest privilege levels in Windows.

By exploiting how WSUS handled certain update requests, attackers could trick the server into executing malicious commands, gaining complete control of the system.

Severity Critical

Active exploitation has been confirmed in the wild, with attackers using this flaw to deploy payloads via WSUS servers exposed on ports 8530 and 8531.

Once exploited, it grants complete system takeover with no user interaction required.

How it impacted organizations

A compromised WSUS server can:

Distribute malicious updates

to every endpoint it manages.

Lateral movement

Distribute malicious updates to every endpoint it manages.

Data exposure

Expose sensitive data and credentials stored or cached on the server.

Privilege escalation

Silently escalate privileges using WSUS’s trusted role in patch management.

With a single WSUS server capable of managing over 100,000 client systems, this flaw turned one of IT’s most trusted tools into a powerful attack vector.

With ADAudit Plus in place, organizations can

 
Active Alerts
  • Detect unusual process creation events (Event 4688) on the WSUS server, such as cmd.exe or powershell.exe launched in the context of service accounts, flagging potential exploitation attempts.
  • Receive immediate alerts for suspicious process activity tied to WSUS exploitation.
  • Review historical activity to pinpoint when and how the compromise occurred.
  • Correlate process tracking with Sysmon auditing to identify attacker movement within the network.
Sysmon auditing

Outcome

With ADAudit Plus organizations would have seen the RCE attack as it unfolded, long before it turned WSUS into a launchpad for network-wide compromise.

More security stories

More story thumbnail

BadSuccessor: The silent domain takeover hiding in plain sight

Security story: Password spraying – How five months of silent credential attacks went undetected

Password spraying: How five months of silence went undetected

Security story: Andariel's RID hijacking – When Windows trusted the wrong account

Andariel's RID hijacking: When Windows trusted the wrong account

Security story: The 2017 S3 breach – How four misconfigured buckets exposed an entire client base

The 2017 S3 breach: When four buckets exposed an entire client base

Schedule a personalized demo with our experts or see ADAudit Plus in action directly from your browser

ADAudit Plus Trusted By