Vulnerability
Exploitation Wave
Security Patch Release
ShadowPad staging through WSUS RCE
Updated 24.11.2025 09:18
Case score 62
Score breakdown
- Total
- 62
- Lead score
- 59
- Support bonus
- +3 / 20
- Scoring support
- 1
- Context members
- 1
Top contributors
- Vulnerability Defines the vulnerable WSUS service, the exploit path, and the ShadowPad delivery chain. base
- Exploitation Wave Confirms live scanning and exploitation attempts, public proof-of-concept risk, and measured WSUS exposure. support
- Security Patch Release Documents emergency out-of-band fixes and temporary workarounds for the same WSUS flaw. context
Case score 62
Members 3
Latest activity 24.11.2025 09:18
Active exploitation
Patch available
CVSS: 9.9 Critical
Active exploitation
Patch available
CVSS: 9.9 Critical
Members 3
First seen 15.10.2025 00:53
Last seen 24.10.2025 19:28
Updated 24.11.2025 09:18
Overview
Attackers are exploiting **CVE-2025-59287** in **Windows Server Update Services (WSUS)** to gain SYSTEM-level execution on exposed Windows Server systems and stage **ShadowPad**. One observed chain used **PowerCat**, `certutil.exe`, and `curl.exe` to reach an external host and install the payload through DLL side-loading.
Microsoft said it fixed the flaw in **October 2025**, and available evidence now shows live scanning and exploitation attempts against public WSUS instances. **Eye Security** and **NCSC-NL** reported that the abuse is active, and Microsoft later issued emergency updates and temporary workarounds for systems that could not be patched immediately.
Attackers are exploiting **CVE-2025-59287** in **Windows Server Update Services (WSUS)** to turn exposed update servers into a live remote-code-execution path. The flaw affects **WSUS-enabled Windows Server** systems and can yield **SYSTEM-level** execution, making public WSUS deployments especially high-risk. Microsoft said it fixed the issue in **October 2025**, and public proof-of-concept code later increased the abuse risk. One observed intrusion chain used **PowerCat** to open a shell, then ran `certutil.exe` and `curl.exe` to contact `149.28.78[.]189:42306` and fetch **ShadowPad**.
The malware was installed through **DLL side-loading** with `ETDCtrlHelper.exe` and `ETDApix.dll`. Eye Security saw scanning and exploitation attempts on **2025-10-24**, and **NCSC-NL** confirmed the activity. Available evidence puts the public WSUS exposure surface at roughly **2,500 instances worldwide**, with about **250 in Germany** and about **100 in the Netherlands**. Available evidence also says at least one customer system was compromised with a different exploit than the HawkTrace proof-of-concept. Microsoft later issued out-of-band security updates for affected Windows Server versions and provided temporary workarounds for systems that could not be patched immediately.