Back to overview

CVE-2025-59287

CRITICAL KEV CISA Exploitation: ACTIVE
9.8
CVSS 3.1

Metadata

CVE ID
CVE-2025-59287
State
PUBLISHED
Assigner
microsoft
Reserved
2025-09-11 19:36 UTC
Published
2025-10-14 17:01 UTC
Last updated
2026-02-26 16:58 UTC
Primary CWE
CWE-502
CWE-502: Deserialization of Untrusted Data
Vendor / Product
Microsoft / Windows Server 2012
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Vendor
Microsoft
Product
Windows
Added to KEV
2025-10-24
Due date
2025-11-14
Ransomware
Not known
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA description
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
Affected products (12)
VendorProductPlatformVersions
Microsoft Windows Server 2012 x64-based Systems 6.2.9200.0 < 6.2.9200.25728
Microsoft Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 < 6.2.9200.25728
Microsoft Windows Server 2012 R2 x64-based Systems 6.3.9600.0 < 6.3.9600.22826
Microsoft Windows Server 2012 R2 (Server Core installation) x64-based Systems 6.3.9600.0 < 6.3.9600.22826
Microsoft Windows Server 2016 x64-based Systems 10.0.14393.0 < 10.0.14393.8524
Microsoft Windows Server 2016 (Server Core installation) x64-based Systems 10.0.14393.0 < 10.0.14393.8524
Microsoft Windows Server 2019 x64-based Systems 10.0.17763.0 < 10.0.17763.7922
Microsoft Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 < 10.0.17763.7922
Microsoft Windows Server 2022 x64-based Systems 10.0.20348.0 < 10.0.20348.4297
Microsoft Windows Server 2022, 23H2 Edition (Server Core installation) x64-based Systems 10.0.25398.0 < 10.0.25398.1916
Microsoft Windows Server 2025 x64-based Systems 10.0.26100.0 < 10.0.26100.6905
Microsoft Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.6905
Weakness (CWE)
CWESourceDescription
CWE-502 cna CWE-502: Deserialization of Untrusted Data
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
References (1)
Back to overview