Microsoft issues emergency security patch for Windows server: update now or risk attack



  • Microsoft issues emergency patch for critical WSUS flaw that allows remote code execution
  • CVE-2025-59287 allows unauthenticated attackers to obtain SYSTEM privileges without user interaction
  • Out-of-band update released after public exploit code appeared online

Microsoft has issued an emergency security patch for Windows Server to fix a critical severity flaw that is apparently being abused.

As part of its most recent cumulative update on Patch Tuesday (October 14, 2025), Microsoft addressed CVE-2025-59287, an “untrusted data deserialization” flaw found in the Windows Server Update Service (WSUS).



Leave a Comment

Your email address will not be published. Required fields are marked *