ShadowPad staging through WSUS RCE
Case score 62
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 62
- Main story score
- 59
- Related evidence lift
- +3 / 20
- Contributing updates
- 1
- Context updates
- 1
- Vulnerability Defines the vulnerable WSUS service, the exploit path, and the ShadowPad delivery chain. main
- Exploitation Wave Confirms live scanning and exploitation attempts, public proof-of-concept risk, and measured WSUS exposure. contributes
- Security Patch Release Documents emergency out-of-band fixes and temporary workarounds for the same WSUS flaw. context
Overview
Latest development Open development history Microsoft discloses WSUS RCE bug Microsoft disclosed CVE-2025-59287, a CVSS 9.8 remote code execution flaw in Windows Server Update Service (WSUS), and tagged it as a vulnerability attackers are more likely to exploit. WSUS is used to centrally distribute and manage updates and patches, so organizations running the service should prioritize remediation to reduce the risk of compromise of the update infrastructure.
-
Public WSUS exposure and PoC risk are confirmed
Eye Security estimated roughly 2,500 WSUS instances worldwide, including 250 in Germany and about 100 in the Netherlands, while the Netherlands National Cyber Security Centre (NCSC-NL) confirmed exploitation of CVE-2025-59287 and warned that publicly available proof-of-concept code increases the risk of abuse.
-
Eye Security observes exploitation attempts
Eye Security observed scanning and exploitation attempts against CVE-2025-59287 on 2025-10-24, and at least one customer system was compromised using a different exploit than the HawkTrace proof-of-concept code.