Impact
An uncaught exception in Windows Server Update Service permits an attacker to tamper with update information over a network. This flaw allows replacement or modification of update catalogs or binaries, potentially delivering malicious or inappropriate content to client computers. The weakness originates from improper input validation and exception handling (CWE‑20 and CWE‑248), enabling unauthorized modification of update data.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025—including Server Core installations—are vulnerable. These systems run Windows Server Update Service and can be compromised when exposed to untrusted network traffic.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while an EPSS score of 1 % shows a very low but nonzero exploitation probability. Not being listed in CISA KEV suggests no widespread exploitation yet. A network‑based attacker who can reach a WSUS endpoint can exploit the flaw without privileged access, enabling unauthorized update tampering or delivery of malicious updates to many client machines.
OpenCVE Enrichment