> cat /dev/github | grep security-tools
discovered 03 Aug 2026

CVE-2025-59287-When-your-patch-server-becomes-the-attack-vector

SQL ★ 10 via github-topic
→ View on GitHub
CVE-2025-59287 refers to a critical unauthenticated remote code execution vulnerability in Windows Server Update Services (WSUS) that can be exploited through unsafe deserialization of attacker-controlled data. The tool illustrates how attackers can leverage this vulnerability via crafted `AuthorizationCookie` payloads to gain SYSTEM-level access on the server, enabling them to deploy malicious updates and pivot within corporate networks. Immediate patching is emphasized, along with recommendations for temporary isolation and detection measures against exploitation attempts.