Actively Exploited in the Wild
This vulnerability is being actively exploited in the wild.
Microsoft Windows Server Update Service Remote Code Execution Vulnerability
Vulnerability
A remote code execution vulnerability has been identified in Windows Server Update Service (WSUS) due to the deserialization of untrusted data. This issue allows an unauthorized attacker to execute code over the network. The vulnerability affects multiple versions of Windows Server, including 2012, 2016, 2019, 2022, and 2025, as well as the Server Core installations of these versions.
Impact
Exploitation of this vulnerability allows for remote code execution on the affected server.
Remediation
Users can download the security update for their specific Windows Server version through the Microsoft Update Catalog. Knowledge Base articles detailing the update are also available.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
