Inside CVE-2025-59287: SoapFormatter RCE in WSUS
While conducting reconnaissance around a month ago, I received a scan result indicating that a target server might be vulnerable to CVE-2025-59287 (1). I reviewed the CVE scan rule and found it too generic to trust on a high-value target. I then examined multiple proof-of-concept implementations across various GitHub repositories, but since the target server was critical, I did not want to execute any PoCs without fully understanding their impact and potential side effects.
-
ProjectDiscovery, “CVE-2025-59287.yaml,” Nuclei Templates, GitHub repository. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-59287.yaml ↩


