Microsoft Critical Out-of-Band Update - 20251027001¶
Overview¶
Since the publication of Advisory 20251015001, Microsoft has released an out-of-band update to address a critical vulnerability that a prior update did not fully mitigate within Windows Server Update Service (WSUS).
What is vulnerable?¶
| Products and Versions Affected | CVE | CVSS | Severity |
|---|---|---|---|
| Vendor noted products and versions | CVE-2025-59287 | 9.8 | Critical |
What has been observed?¶
The WASOC has not received any reports of exploitation of this vulnerability on Western Australian Government networks at the time of writing.
Recommendation¶
The WASOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframes (refer Patch Management):
- Microsoft CVE Article: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287