目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-59287 PoC — Microsoft Windows Server 代码问题漏洞

来源
关联漏洞
标题: Microsoft Windows Server 代码问题漏洞 (CVE-2025-59287)
Description:Microsoft Windows Server是美国微软(Microsoft)公司的一套服务器操作系统。 Microsoft Windows Server存在代码问题漏洞,该漏洞源于攻击者利用该漏洞可以远程执行代码。
Description
powershell version of hawktrace POC exploit
介绍
# CVE-2025-59287-WSUS
powershell version of hawktrace POC exploit
https://hawktrace.com/blog/CVE-2025-59287-UNAUTH

1: edit the variables in the script (url, port, etc)

2: start netcat listener

3: run script - it will auto download ysoserial.net, generate the payload and send exploit to WSUS server

this will generate a new computer in your console named hawktrace.local

<img width="645" height="147" alt="image" src="https://github.com/user-attachments/assets/d49dbf2b-fe30-4a5f-9e48-e336685432a2" />



4: (re)open the WSUS console to trigger the exploit. 

the console will run into an error

<img width="830" height="281" alt="image" src="https://github.com/user-attachments/assets/379d202d-a048-4880-a51c-96fd68a7c83f" />

but this triggers the reverse shell and connect you your kali:

<img width="512" height="120" alt="image" src="https://github.com/user-attachments/assets/804c8655-9463-41df-881d-fda2ba5d2305" />



# Testing / Infos
tested on (unpatched) server 2022, wsus version 10.0.20348.1
<img width="712" height="319" alt="image" src="https://github.com/user-attachments/assets/dfe3b98c-ba61-44fd-aaf9-8e9ef422a683" />

use at your own risk. no support, no guarantees.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →