> cat /dev/github | grep security-tools

Sql

CVE-2025-59287-When-your-patch-server-becomes-the-attack-vector

2026-08-03 SQL ★ 10
CVE-2025-59287 refers to a critical unauthenticated remote code execution vulnerability in Windows Server Update Services (WSUS) that can be exploited through unsafe deserialization of attacker-controlled data. The tool illustrates how attackers can leverage this vulnerability via crafted `AuthorizationCookie` payloads to gain SYSTEM-level access on the server, enabling them to deploy malicious updates and pivot within corporate networks. Immediate patching is emphasized, along with recommendations for temporary isolation and detection measures against exploitation attempts.