Close Menu
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    KahawatunguKahawatungu
    Button
    • NEWS
    • BUSINESS
    • KNOW YOUR CELEBRITY
    • POLITICS
    • TECHNOLOGY
    • SPORTS
    • HOW-TO
    • WORLD NEWS
    KahawatunguKahawatungu
    TECHNOLOGY

    Critical Windows Server Flaw Exploited by Hackers, Microsoft Urges Immediate Patch

    David WafulaBy David WafulaOctober 27, 2025No Comments2 Mins Read
    Facebook Twitter WhatsApp Telegram Email
    Critical Windows Server Flaw Exploited by Hackers Microsoft Office Online Server Office
    Share
    Facebook Twitter WhatsApp Telegram Pinterest Email Copy Link

    A serious security flaw has been discovered in Microsoft’s Windows Server Update Services (WSUS), and experts warn it is already being exploited by hackers. The vulnerability, identified as CVE-2025-59287, carries a severity score of 9.8 out of 10, making it one of the most dangerous recent threats to Windows servers.

    The flaw was revealed earlier this month and stems from the deserialization of untrusted data in WSUS, which IT administrators use to manage and distribute Windows updates within organizations. According to cybersecurity firm Huntress, attackers are using the bug to gain full control over vulnerable servers.

    Researchers at Hawktrace, who discovered the issue, explained that it occurs in how WSUS handles encrypted cookies. A crafted request sent to certain endpoints can allow an attacker to execute code remotely with system-level privileges — effectively taking over the server.

    After Microsoft released an emergency update on October 23, Huntress reported that hackers began targeting publicly exposed WSUS web services almost immediately. These attackers used proxy networks to hide their locations and sent malicious commands that gathered user and network data from infected systems before sending it to remote servers.

    Also Read: ChatGPT’s new browser has potential, if you’re willing to pay

    Huntress said only a small number of systems appear vulnerable since WSUS is rarely exposed online, noting that just 25 instances were found open on the targeted network ports (8530 and 8531). Even so, the company urged all users to take the threat seriously.

    Microsoft has released security updates for Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. Users with automatic updates enabled will receive the fix automatically, but those who update manually can find the patch in the Microsoft Update Catalog.

    For systems that cannot be patched immediately, Microsoft recommends blocking inbound traffic on ports 8530 and 8531 to prevent attacks, though this will temporarily disable WSUS updates. Servers without the WSUS role enabled are not affected.

    Cybersecurity experts are warning organizations to act quickly. “Attackers are exploiting this in real time. Systems should be patched or taken offline until they are secured,” Huntress cautioned.

     

    Email your news TIPS to Editor@Kahawatungu.com — this is our only official communication channel

    Follow on Facebook Follow on X (Twitter)
    Share. Facebook Twitter WhatsApp LinkedIn Telegram Email
    David Wafula

    Related Posts

    Odhiambo Questions High Court’s Decision to Uphold Gachagua Impeachment Despite Rights Violation Finding

    June 9, 2026

    OpenAI plans to go public, intensifying investment race with Anthropic

    June 9, 2026

    Apple unveils Siri AI makeover as Tim Cook bids farewell

    June 9, 2026

    Comments are closed.

    Latest Posts

    Court suspends finding on teleradiology firm over privacy issue 

    June 12, 2026

    Banks Get Three More Years to Meet Sh10 Billion Capital Requirement

    June 12, 2026

    Committee Backs Bill to Regulate Dental and Optical Practitioners

    June 12, 2026

    Senators Push for Recognition of Wagazinja Community

    June 12, 2026

    Senator Seeks Answers Over Sh1 Billion Worth of Expired Drugs at KEMSA

    June 12, 2026

    Omtatah Questions KPC Ownership Disclosure

    June 12, 2026

    Kuwait Clarifies Kenya Domestic Workers Issue, Says Suspension Was Imposed by Kenya

    June 12, 2026

    Missing man found dead in suspected fall while harvesting honey in Kitui

    June 12, 2026
    Facebook X (Twitter) Instagram Pinterest
    © 2026 Kahawatungu.com. Designed by Okii.

    Type above and press Enter to search. Press Esc to cancel.