¡¾·ì϶¹«¸æ¡¿Windows ·þÎñÆ÷¸üзþÎñ (WSUS) Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-59287)

°ä²¼¹¦·ò 2025-10-23

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Windows ·þÎñÆ÷¸üзþÎñ (WSUS) Ô¶³Ì´úÂëÖ´Ðзì϶

CVE   ID

CVE-2025-59287

·ì϶ÀàÐÍ

RCE

·¢ÏÖ¹¦·ò

2025-10-23

·ì϶ÆÀ·Ö

9.8

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Microsoft Windows Server Update Services(WSUS)ÊÇÒ»¿îÓÉ΢Èí¿ª·¢µÄ·þÎñÆ÷ÖÎÀí¹¤¾ß£¬ÓÃÓÚ¼¯ÖÐÖÎÀíºÍ·Ö·¢Windows²Ù×÷ϵͳ¼°ÆäËû΢Èí²úÆ·µÄ¸üС£WSUSÔÊÐíITÖÎÀíÔ±ÔÚÆóÒµÍøÂçÖв¿Êð²¹¶¡ºÍ¸üУ¬È·±£¸÷¸ö¿Í»§¶ËϵͳµÄ°²È«ÐԺͲ»±äÐÔ¡£Í¨¹ýWSUS£¬ÖÎÀíÔ±Äܹ»Ñ¡ÔñÌØ¶¨µÄ¸üУ¬½øÐвâÊÔºÍÑéÖ¤£¬²¢½«ÆäÍÆË͵½×éÖ¯ÖеÄËùÓÐÍÆËã»ú¡£´Ë±í£¬WSUS»¹ÌṩÁ˾ßÌåµÄ»ã±¨Ö°ÄÜ£¬Ô®ÊÖÖÎÀíÔ±¼à¿Ø¸üеÄ״̬ºÍ²¿Êð½ø¶È¡£


2025Äê10ÔÂ23ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Ò»¸öÓ°ÏìMicrosoft Windows Server Update Services(WSUS)µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬Ô´ÓÚ²»°²È«µÄ·´ÐòÁл¯¹ý³Ì¡£¸Ã·ì϶²úÉúÔÚWSUS´¦ÖÃAuthorizationCookieʱ£¬Ê¹ÓÃ.NETµÄBinaryFormatter¶Ô¼ÓÃܵÄCookieÊý¾Ý½øÐз´ÐòÁл¯£¬µ«Î´¶ÔÀàÐͽøÐÐÑϸñÑéÖ¤¡£¹¥»÷ÕßÄܹ»»ú¹Ø¶ñÒâ¼ÓÃÜÊý¾Ý£¬Í¨¹ýGetCookie()½Ó¿Ú·¢ËÍ£¬µ¼ÖÂϵͳִÐÐËÁÒâ´úÂ룬²¢ÒÔSYSTEMȨÏÞÔËÐУ¬·ì϶ÆÀ·Ö9.8·Ö£¬·ì϶¼¶±ðÑϳÁ¡£


¶þ¡¢Ó°ÏìÁìÓò


Windows Server 2025 (Server Core installation)

Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows Server 2025
Windows Server 2022, 23H2 Edition (Server Core installation)


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


Microsoft¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬ÒÔ½¨¸´¸Ã·ì϶¡£


ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287/
https://gist.github.com/hawktrace/880b54fb9c07ddb028baaae401bd3951
https://hawktrace.com/blog/CVE-2025-59287