Executive brief
A vulnerability in the Windows Server Update Service (WSUS) could allow an unauthorized attacker to disrupt the update process across a network. WSUS is a critical tool used by organizations to manage and distribute software updates to computers within their environment. An exploit could lead to a denial of service, preventing systems from receiving essential security patches and potentially impacting overall network stability.
Technical details
A vulnerability exists in Windows Server Update Service (WSUS) due to improper input validation leading to an uncaught exception (CWE-248). An unauthenticated attacker can exploit this over the network without user interaction. While the advisory mentions 'tampering,' the provided CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) specifically indicates a high impact on availability, suggesting a Denial of Service (DoS) condition. Affected versions include various releases of Windows 10 and Windows Server (2012 through 2019). Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Server Update Service (WSUS) Windows 10, Windows Server 2012, 2016, 2019
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory