Security Research

CVE-2025-52287 WSUS Deserialization to RCE: Four-Stage Exploitation via SimpleAuth Cookie Chain

#Vulnerability Analysis#Code Audit#Cyber Attack#Lateral Movement
CVE-2025-52287 WSUS Deserialization to RCE: Four-Stage Exploitation via SimpleAuth Cookie Chain

WSUS treats the SimpleAuth plugin’s authentication Cookie as “verified trust”, but the chain that generates the Cookie has no strict deserialization protection — attackers use a 4-stage attack (obtain session ID, get auth Cookie, use Cookie to trigger SimpleAuth, inject malicious .NET deserialization payload) to gain RCE on the patch distribution center.

Unlock to view this content.