Deserialization of Untrusted Data in Windows Server - CVE-2025-59287
Published: October 15, 2025 / Updated: February 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker send a crafted event that triggers unsafe object deserialization in a legacy serialization mechanism and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2025-59287
Links to Public Exploits and PoC-codes
- Exploit #12454 - CVE-2025-59287 (February 27, 2026)
- Exploit #12165 - CVE-2025-59287-PoC (Unauthenticated RCE PoC in Microsoft Windows Server Update Service (WSUS) - CVE-2025-59287 & CVE-2023-35317) (November 28, 2025)
- Exploit #12100 - Windows Server Update Service Deserialization Remote Code Execution (November 12, 2025)
- Exploit #12097 - WSUS-CVE-2025-59287-RCE (November 7, 2025)
- Exploit #12095 - CVE-2025-59287 (November 7, 2025)
- Exploit #12093 - CVE-2025-59287 (November 7, 2025)
- Exploit #12082 - cve-2025-59287-exploit-poc (November 7, 2025)
- Exploit #12062 - CVE-2025-59287 (October 31, 2025)
- Exploit #12055 - Breaking-the-Update-Chain-Inside-CVE-2025-59287-and-the-WSUS-RCE-Threat (CVE-2025-59287 is a critical RCE vulnerability in Windows Server Update Services (WSUS) caused by unsafe deserialization of untrusted data. It allows remote attackers to execute arbi (October 31, 2025)
- Exploit #12054 - CVE-2025-59287 (October 31, 2025)
- Exploit #12051 - CVE-2025-59287 (October 31, 2025)