back to article Microsoft drops surprise Windows Server patch before weekend downtime

Microsoft has released an out-of-band update to patch a critical vulnerability in Windows Server Update Services (WSUS). The update addresses CVE-2025-59287">CVE-2025-59287, a remote code execution flaw affecting Windows Server versions 2012 through 2025. The vulnerability stems from insecure deserialization of untrusted data …

  1. m4r35n357 Silver badge

    Context, wot's that?

    "However Microsoft's message to administrators is clear: switch to an alternative"

    1. LVPC Bronze badge

      Re: Context, wot's that?

      >> However Microsoft's message to administrators is clear: switch to an alternative like its cloud-based Intune service.

      People still use Microsoft for servers? What sort of insanity in this day and age!

      1. kmorwath

        Re: Context, wot's that?

        Aks F5 or RedHat how much secure was running on Linux, in the past weeks...

    2. kmorwath

      Re: Context, wot's that?

      A cloud based alternative is not an alternative when you use WSUS because your connection is slow enough that several machine attempts to download updates in the gigabyte range is not an option. For the same reason you may have Linux mirrors or at least an apt cache or the like. Or you may wan faster deployment of spun-up VMs dowloading files from the local server.

      But it is true that WSUS have not been updated for ages, it has known issues that could be solved with some database tuning, and others that only MS can fix, but for some reason keeping machines patched wasn't one of their main priorities...

    3. Fred Daggy
      Linux

      Re: Context, wot's that?

      My message to Microsoft : Pull your finger out of your arse and start supporting your damn on-premises systems as first class citizen.

      Fix and update WSUS and other so-called “depreciated” systems. You’ve very little that keeps us in your ecosystem. That includes operating system, cloud platform, productivity suite, database and messaging. Competitors on all fronts, get your act together.

  2. may_i Silver badge

    Only a serious vulnerability if you've already lost your mind.

    > block inbound traffic to ports 8530 and 8531

    Why would anyone, except for reasons of insanity, expose ANY ports on a Windows machine to the Internet at large?

    1. Jou (Mxyzptlk) Silver badge

      Re: Only a serious vulnerability if you've already lost your mind.

      Because there is another way more common reason: Stupidity. Worse that insanity.

    2. Sandtitz Silver badge
      Boffin

      Re: Only a serious vulnerability if you've already lost your mind.

      The MS CVE article talks about using the host's own (Windows) firewall to block access until patching is done. Shirley no-one is exposing WSUS to internet.

      This is about zero trust. All your systems should be siloed microsegmented with only the minimum required inbound/outbound access allowed. WSUS should be in its own VLAN, different to the client computers anyway, so you can control and monitor all connections with a firewall.

      "Why would anyone, except for reasons of insanity, expose ANY ports on a Windows machine to the Internet at large?"

      Please explain how e.g. latest patched Apache Tomcat is more secure when served from Linux instead of Windows.

  3. Anonymous Coward
    Anonymous Coward

    "However Microsoft's message to administrators is clear: switch to an alternative like its cloud-based Intune service."

    Intune can only be used for client versions of Windows. If you use WSUS to update servers then the cloudy equivalent for them is Azure Update Manager, which is part of Azure Arc.

    1. Anonymous Coward
      Anonymous Coward

      Which in itself is problematical if you're trying to be multi-cloud, with little-to-no dependence on a single cloud provider (which when push comes to shove may turn out to be an illusion).

  4. Jou (Mxyzptlk) Silver badge

    "If the WSUS Server Role is enabled on your server, disable it."

    "If the WSUS Server Role is enabled on your server, disable it. Note that clients will no longer receive updates from the server if WSUS is disabled."

    Gotta love that humor in the msrc article...

    At least it is included int the normal updates for Windows server and not a separate patch...

  5. ABugNamedJune

    I don't think anything will happen at my org, but of course it had to be over the weekend *I'm* on call. Couldn't you have waited one more week?

  6. Paul Hovnanian Silver badge

    Apropos article graphic ...

    ... for a Windows repair: A hammer.

  7. Taliesinawen

    Good Grief Charlie brown :o

    Deserialization of untrusted data: The vulnerability arises from unsafe deserialization in WSUS, where objects sent over a network like AuthorizationCookie data, are improperly validated and converted back into executable objects

  8. saltycupcakes
    1. The Dark Side Of The Mind (TDSOTM)
      Pint

      I saw what you did here.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon