Microsoft WSUS: Emergency Update Patches Critical Code Injection Vulnerability

Microsoft WSUS: Emergency Update Patches Critical Code Injection Vulnerability

Microsoft released an emergency update for a critical security vulnerability in WSUS on Friday morning.

According to Microsoft, the update correctly closes a critical security vulnerability that attackers could use to inject and execute malicious code.

Microsoft has discovered a remote code execution vulnerability (RCE) in the reporting web service of Windows Server Update Services (WSUS).

An out-of-band update was released to address the issue, and admins should act quickly to apply the new patch, as a proof-of-concept exploit has reportedly surfaced.

The update was announced in the Windows Release Health Message Center at 4 AM Central European Summer Time on Friday morning.

Author's summary: Microsoft releases emergency WSUS update.

more

heise online heise online — 2025-10-24

More News