This detection identifies adversary activity exploiting a critical remote code execution vulnerability in Windows Server Update Services (WSUS), which could allow attackers to execute arbitrary commands and gain initial access to update infrastructure. Proactive hunting for this threat is essential within Azure Sentinel to prevent potential lateral movement and widespread compromise, given that WSUS servers are often highly privileged targets central to the organization’s patching ecosystem.
rule EXPL_WSUS_Exploitation_Indicators_Oct25 {
meta:
description = "Detects indicators related to the exploitation of the Windows Server Update Services (WSUS) Remote Code Execution Vulnerability (CVE-2025-59287)"
author = "Florian Roth"
reference = "https://www.huntress.com/blog/exploitation-of-windows-server-update-services-remote-code-execution-vulnerability"
date = "2025-10-25"
score = 75
id = "9a118d85-fbcd-5476-acd8-6bf66f660368"
strings:
// Error traceback found in C:\Program Files\Update Services\Logfiles\SoftwareDistribution.log
$sl1 = "at System.Data.DataSet.DeserializeDataSetSchema(SerializationInfo info, StreamingContext context" ascii wide
$sl2 = "at System.Runtime.Serialization.ObjectManager.DoFixups()" ascii wide
$sl3 = "at System.Runtime.Serialization.ObjectManager.CompleteISerializableObject" ascii wide
$sl4 = "System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation." ascii wide
$sl5 = "ErrorWsusService.9HmtWebServices.CheckReportingWebServiceReporting WebService WebException:System.Net.WebException: Unable to connect to the remote server" ascii wide
// Encoded PowerShell command observed in exploitation attempts
$se1 = "powershell -ec try{$r= (&{echo https://" ascii wide base64 base64wide
$se2 = ":8531; net user /domain; ipconfig " ascii wide base64 base64wide
// Commands observed in follow-up activity
$sa1 = "whoami;net user /domain" ascii wide base64 base64wide
$sa2 = "net user /domain; ipconfig /all" ascii wide base64 base64wide
condition:
all of ($sl*)
or 1 of ($se*)
or all of ($sa*)
}
This YARA rule can be deployed in the following contexts:
This rule contains 10 string patterns in its detection logic.
Scenario: Scheduled WSUS Synchronization via PowerShell
WSUS service account runs a custom PowerShell script (Start-WSUSSync.ps1) to trigger content synchronization from Microsoft Update. This activity generates HTTP POST requests to the /Content/Download endpoint, which mimics the payload structure of the RCE exploit.WSUS_SVC service account (e.g., DOMAIN\WSUS_Service) where the User-Agent header contains “PowerShell” and the destination port is 8530 or 443, provided the request URI does not contain the suspicious parameter pattern identified in CVE-2025-59287.Scenario: Third-Party Patch Management Integration
10.20.50.x) and filter out events where the HTTP method is GET or the payload size exceeds 5MB, as legitimate integration queries often involve large metadata downloads rather than RCE injection attempts.Scenario: Automated Health Monitoring by Zabbix/Prometheus