Executive brief
Microsoft Windows Server Update Service (WSUS) is a tool used by IT administrators to manage and distribute software updates across corporate networks. A critical security flaw allows an unauthorized attacker to remotely take control of the server by sending specially crafted data. This could lead to a total compromise of the update infrastructure, potentially allowing the attacker to deploy malicious software to all connected computers in the organization.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in Microsoft Windows Server Update Service (WSUS). The flaw is rooted in how the service processes incoming data over the network, allowing an unauthenticated attacker to trigger the execution of arbitrary code. The attack vector is network-based and requires no user interaction or prior privileges. Successful exploitation grants the attacker high-level access to the WSUS server, which can be leveraged for lateral movement or infrastructure-wide compromise. Microsoft has released security updates to address this vulnerability, which is confirmed to be exploited in the wild.
Affected products
- Microsoft Windows Server Update Service (WSUS) Windows Server 2012, 2012 R2, 2016, 2019, 2022, 23H2, 2025
Timeline
- 2025-10-14: disclosed: Initial disclosure by Microsoft Corporation
- 2025-10-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-10-24: advisory: NVD publication date