CVE-2025-59287 — exposed on the internet
CVE-2025-59287: CWE-502: Deserialization of Untrusted Data in Microsoft Windows Server 2012
Internet exposure observed by OffSeq scans · last 30 days
1
Exposed hosts
9.8
CVSS
99.9%
EPSS
Found on 1 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.
About CVE-2025-59287
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Vendor: MicrosoftCWE-502
OffSeq internet scanning found CVE-2025-59287 on 1 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.
Exposed-host countries
Exposed via
http
References
NVD — CVE-2025-59287OffSeq Radar — CVE-2025-59287https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287https://gist.github.com/hawktrace/880b54fb9c07ddb028baaae401bd3951https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59287https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windows-server-wsus-flaw-exploited-in-attacks/https://hawktrace.com/blog/CVE-2025-59287https://www.vicarius.io/vsociety/posts/cve-2025-59287-detection-script-rce-vulnerability-in-windows-server-update-servicehttps://www.vicarius.io/vsociety/posts/cve-2025-59287-mitigation-script-rce-vulnerability-in-windows-server-update-service