Hackers Exploit Critical Windows Server Update Service Vulnerability

by Anika Shah - Technology
0 comments

Critical Windows Server Vulnerability Exploited in attacks

security researchers are warning that cyber threat actors are abusing a critical vulnerability in Microsoft Windows Server Update Service.

The vulnerability,tracked as CVE-2025-59287, involves deserialization of untrusted data and could allow intruders to execute code without authorization.

researchers at Huntress said they have seen attackers exploiting the vulnerability in four diffrent customers’ networks.

Senior security researcher John Hammond described the attack as a simple “point-and-shoot” technique, noting that the recent release of a proof of concept made the attack trivially accessible for any hacker to launch.

Microsoft issued out-of-band security updates on Thursday to address the vulnerability. “We rereleased this CVE after identifying that the initial update did not fully mitigate the issue,” a Microsoft spokesperson told Cybersecurity Dive.

Related Posts

Leave a Comment