Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "r2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.14393.8524"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.17763.7922"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.20348.4297"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.25398.1916"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.26100.6905"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59287.json"