Close Menu
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    KahawatunguKahawatungu
    Button
    • NEWS
    • BUSINESS
    • KNOW YOUR CELEBRITY
    • POLITICS
    • TECHNOLOGY
    • SPORTS
    • HOW-TO
    • WORLD NEWS
    KahawatunguKahawatungu
    TECHNOLOGY

    Critical Windows Server Flaw Exploited by Hackers, Microsoft Urges Immediate Patch

    David WafulaBy David WafulaOctober 27, 2025No Comments2 Mins Read
    Facebook Twitter WhatsApp Telegram Email
    Critical Windows Server Flaw Exploited by Hackers Microsoft Office Online Server Office
    Share
    Facebook Twitter WhatsApp Telegram Pinterest Email Copy Link

    A serious security flaw has been discovered in Microsoft’s Windows Server Update Services (WSUS), and experts warn it is already being exploited by hackers. The vulnerability, identified as CVE-2025-59287, carries a severity score of 9.8 out of 10, making it one of the most dangerous recent threats to Windows servers.

    The flaw was revealed earlier this month and stems from the deserialization of untrusted data in WSUS, which IT administrators use to manage and distribute Windows updates within organizations. According to cybersecurity firm Huntress, attackers are using the bug to gain full control over vulnerable servers.

    Researchers at Hawktrace, who discovered the issue, explained that it occurs in how WSUS handles encrypted cookies. A crafted request sent to certain endpoints can allow an attacker to execute code remotely with system-level privileges — effectively taking over the server.

    After Microsoft released an emergency update on October 23, Huntress reported that hackers began targeting publicly exposed WSUS web services almost immediately. These attackers used proxy networks to hide their locations and sent malicious commands that gathered user and network data from infected systems before sending it to remote servers.

    Also Read: ChatGPT’s new browser has potential, if you’re willing to pay

    Huntress said only a small number of systems appear vulnerable since WSUS is rarely exposed online, noting that just 25 instances were found open on the targeted network ports (8530 and 8531). Even so, the company urged all users to take the threat seriously.

    Microsoft has released security updates for Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. Users with automatic updates enabled will receive the fix automatically, but those who update manually can find the patch in the Microsoft Update Catalog.

    For systems that cannot be patched immediately, Microsoft recommends blocking inbound traffic on ports 8530 and 8531 to prevent attacks, though this will temporarily disable WSUS updates. Servers without the WSUS role enabled are not affected.

    Cybersecurity experts are warning organizations to act quickly. “Attackers are exploiting this in real time. Systems should be patched or taken offline until they are secured,” Huntress cautioned.

     

    Email your news TIPS to Editor@Kahawatungu.com — this is our only official communication channel

    Follow on Facebook Follow on X (Twitter)
    Share. Facebook Twitter WhatsApp LinkedIn Telegram Email
    David Wafula

    Related Posts

    Oracle shares slide as earnings fail to ease AI bubble fears

    December 11, 2025

    Protecting business data: How to prevent unauthorized access? 

    December 9, 2025

    Trump gives Nvidia green light to sell advanced AI chips to China

    December 9, 2025

    Comments are closed.

    Latest Posts

    Govt Postpones Religious Bill to Allow Wider Public Input

    December 13, 2025

    Ruto, CSs Makes Key Govt Appointments

    December 13, 2025

    How To Draw A Robin

    December 13, 2025

    How To Draw A Protea

    December 13, 2025

    How To Draw A Pretty Flower

    December 13, 2025

    How To Draw A Pineapple

    December 13, 2025

    How To Draw A Person Easy

    December 13, 2025

    Aviva Drescher Net Worth

    December 13, 2025
    Facebook X (Twitter) Instagram Pinterest
    © 2025 Kahawatungu.com. Designed by Okii.

    Type above and press Enter to search. Press Esc to cancel.