
CVE-2025-59287: When the patch server becomes the attack vector
Year of occurrence: 2025 (disclosed and CVE issued)The vulnerability CVE-2025-59287 (WSUS Remote Code Execution)
A critical remote code execution (RCE) flaw in Windows Server Update Services (WSUS), tracked as CVE-2025-59287, allowed attackers to run arbitrary code as SYSTEM, one of the highest privilege levels in Windows.
By exploiting how WSUS handled certain update requests, attackers could trick the server into executing malicious commands, gaining complete control of the system.
Severity Critical
Active exploitation has been confirmed in the wild, with attackers using this flaw to deploy payloads via WSUS servers exposed on ports 8530 and 8531.
Once exploited, it grants complete system takeover with no user interaction required.
How it impacted organizations
A compromised WSUS server can:
Distribute malicious updates
to every endpoint it manages.
Lateral movement
Distribute malicious updates to every endpoint it manages.
Data exposure
Expose sensitive data and credentials stored or cached on the server.
Privilege escalation
Silently escalate privileges using WSUS’s trusted role in patch management.
With a single WSUS server capable of managing over 100,000 client systems, this flaw turned one of IT’s most trusted tools into a powerful attack vector.
With ADAudit Plus in place, organizations can
- Detect unusual process creation events (Event 4688) on the WSUS server, such as cmd.exe or powershell.exe launched in the context of service accounts, flagging potential exploitation attempts.
- Receive immediate alerts for suspicious process activity tied to WSUS exploitation.
- Review historical activity to pinpoint when and how the compromise occurred.
- Correlate process tracking with Sysmon auditing to identify attacker movement within the network.
Outcome
With ADAudit Plus organizations would have seen the RCE attack as it unfolded, long before it turned WSUS into a launchpad for network-wide compromise.
