KB5070882: Windows Server 2016 WSUS RCE (CVE-2025-59287)

critical Nessus Plugin ID 271439

Version 1.4

Nov 12, 2025, 12:37 AM

  • Plugin metadata (updating description to outline plugin logic)

Plugin Feed: 202511120037

Version 1.3

Oct 30, 2025, 11:01 PM

  • Logic Changes (removed CVE from defective MS patches, added EXE checking to avoid systems with removed wsus roles)

Plugin Feed: 202510302301

Version 1.2

Oct 26, 2025, 10:11 PM

  • CISA reference
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:F/RL:OF/RC:C")
  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:F/RL:O/RC:C")
  • Exploit attributes ("Exploit available" set to "True")
  • Exploit attributes ("Exploitability ease" set to "Exploits are available")

Plugin Feed: 202510262211

Version 1.1

Oct 25, 2025, 9:33 PM

  • New

Plugin Feed: 202510252133

* Changelogs are generally available for changes made after Nov 1, 2022