CVE-2025-59287
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
- Published Oct 14, 2025
- CVSS 9.8 critical
- 100.0% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
Affected software
In the news
- VulnCheck Research Highlights: November 2025 VulnCheck Blog ·