MC1178653 High
Take Action: Out-of-band update to address a vulnerability in Windows Server Update Services (WSUS)
Summary AI-generated
A critical RCE vulnerability in WSUS reporting web service is fixed by an out-of-band Windows Server update released on 2025-10-23; immediate installation is recommended.
Suggested actions AI-generated
- Install the October 23, 2025 out-of-band update
- Reboot affected Windows Server systems
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1285472 Take action: Out-of-band updates released for Windows Server to address two issues
- MC1199746 Take Action: Out-of-band update to address MSMQ service issues leading to queue operations and resource-related errors
- MC1180840 An updated version of the October 2025 Scan Cab is available
- MC1471876 Take Action: Out-of-band update released to address issues from the September 2026 Windows security update
- MC1179337 An updated version of the October 2025 Scan Cab is available
- MC1188558 Take Action: Out-of-band update to address November 2025 hotpatch update being reoffered after Windows update scan
Original post from Microsoft
Microsoft has identified a remote code execution (RCE) vulnerability in the Windows Server Update Services (WSUS) reporting web service. Windows servers that do not have the WSUS server role enabled are not vulnerable to this vulnerability. For more information about the security fix, see CVE-2025-59287.
An out-of-band (OOB) update was released today, October 23, 2025, to address this issue. This is a cumulative update, so you do not need to apply any previous updates before installing this update, as it supersedes all previous updates for affected versions. If you haven’t installed the October 2025 Windows security update yet, we recommend you apply this OOB update instead. After you install the update you will need to reboot your system.
If you have not yet deployed the October 2025 Windows security update and your IT environment includes devices running on the versions of Windows listed below, we recommend you apply this OOB update instead: