Impact
The vulnerability is a missing authentication check for a critical function in Windows Server Update Service that permits an attacker who already has network access to the WSUS server to elevate privileges. This flaw enables the attacker to bypass authentication and gain elevated rights, potentially compromising the WSUS deployment. The weakness corresponds to CWE-306.
Affected Systems
Microsoft Windows 10 Version 1607, Microsoft Windows 10 Version 1809, Microsoft Windows Server 2012, Microsoft Windows Server 2012 (Server Core installation), Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012 R2 (Server Core installation), Microsoft Windows Server 2016, Microsoft Windows Server 2016 (Server Core installation), Microsoft Windows Server 2019, Microsoft Windows Server 2019 (Server Core installation), Microsoft Windows Server 2022, Microsoft Windows Server 2025, and Microsoft Windows Server 2025 (Server Core installation).
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% signals a very low probability of active exploitation at present. This flaw is not listed in the CISA KEV catalog, so the exposure risk is limited to environments that run WSUS. The description specifies that the attacker must be authorized and able to reach the WSUS service over a network; consequently, the most likely attack vector is an internal attacker or a compromised host with network connectivity to the WSUS server. By sending specially crafted requests to the unprotected WSUS API, an attacker can bypass authentication and acquire privileged access within the WSUS service.
OpenCVE Enrichment