Close Menu
Nabka News
  • Home
  • News
  • Business
  • China
  • India
  • Pakistan
  • Political
  • Tech
  • Trend
  • USA
  • Sports

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Trump firing of Fed’s Lisa Cook case set for January

November 12, 2025

WNBA Las Vegas Aces’ Becky Hammon says league may need new leadership

November 12, 2025

AI startup Code Metal raises $36 million in funding round led by Accel

November 12, 2025
Facebook X (Twitter) Instagram
  • Home
  • About NabkaNews
  • Advertise with NabkaNews
  • DMCA Policy
  • Privacy Policy
  • Terms of Use
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Nabka News
  • Home
  • News
  • Business
  • China
  • India
  • Pakistan
  • Political
  • Tech
  • Trend
  • USA
  • Sports
Nabka News
Home » Windows server vulnerability identified by PKCERT
Pakistan

Windows server vulnerability identified by PKCERT

i2wtcBy i2wtcNovember 12, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp Copy Link
Follow Us
Google News Flipboard Threads
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


Pakistan’s national cyber-incident response body, Pakistan Computer Emergency Response Team, has issued a critical security advisory concerning a high-risk vulnerability in Microsoft Windows Server Update Services, the software used by many organisations for patch management of Windows servers.

Microsoft Windows Server Update Services (WSUS) is the central system that large organisations (like government offices or major companies) use to manage, distribute, and install updates (patches) across their entire network of computers. The exploit works by unsafe deserialisation of the WSUS Authorisation Cookie: the attacker sends a corrupted permission note, like a cookie, to the server that tricks the system into executing the attacker’s own code instead of ignoring the bad input.

The flaw allows for remote control execution (RCE) of a compromised system, which means that an attacker can remotely run their own malicious programs or commands on the vulnerable server from anywhere in the world, “leading to complete server compromise,” according to the Pakistan Computer Emergency Response Team (PKCERT) advisory. The attacker is “unauthenticated”, meaning they require no username or password to exploit this vulnerability, and PKCERT has said that this flaw is being “actively exploited in the wild.”

How does this happen?

Serialising is when a web application converts complex data, like your session information or website permissions, into a compact format for easy sending and storage. When the information needs to be used again, the application then deserialises the information.

“Unsafe deserialisation” happens when a program blindly trusts data it’s deserialising, meaning it doesn’t check whether that data has been tampered with. If an attacker can modify that data —a cookie, token, or hidden field — and the server deserialises it without verification, the attacker can inject malicious code or commands that run on the server’s side.

In this case, the WSUS Authorisation Cookie (a piece of data WSUS uses to know who’s connecting and what they can do) is not properly validated before being deserialised. Since WSUS servers manage updates across entire networks, a compromised WSUS host could push infected updates to thousands of connected machines, spreading malware or ransomware silently across corporate and government systems, stealing and transferring authentication and network data, or take full system control of all machines on a network (they can run any code they want).

According to PKCERT, they have given this vulnerability score on the Common Vulnerability Scoring System a value of 9.8, meaning a critical threat to national public and private systems. Any organisation is at risk if they have Windows systems that are not running the most updated versions, as well as systems that are publicly accessible, among others.

Combating the exploit

PKCERT has issued a few solutions to the problem. They recommend applying Microsoft’s October 2025 out-of-band patch (a patch that was released outside of the normal patch cycle), temporarily blocking affected Internet ports, which act as doorways on your computer that let specific types of online traffic go in and out, and strengthening server security, like ensuring WSUS servers aren’t exposed to the public internet.

They also call on organisations to be more vigilant with suspicious cyber activity and to track unauthorised server access to ensure the security of their organisations.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp Copy Link
i2wtc
  • Website

Related Posts

Pakistan

Action on PTI dissident Senator’s resignation halted ahead of 27th Amendment vote

November 12, 2025
Pakistan

Car sales surge 32% in October with cheaper loans bringing buyers back

November 12, 2025
Pakistan

Pakistan to host ASOCIO Digital Summit next year

November 12, 2025
Pakistan

Ex-CJP Jawwad S Khawaja challenges 27th Amendment in SC

November 12, 2025
Pakistan

holds grand peace jirga to address terrorism, security, development

November 12, 2025
Pakistan

Maryam declares war on smog at COP-30

November 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

House Republicans unveil aid bill for Israel, Ukraine ahead of weekend House vote

April 17, 2024

Prime Minister Johnson presses forward with Ukraine aid bill despite pressure from hardliners

April 17, 2024

Justin Verlander makes season debut against Nationals

April 17, 2024

Tesla lays off 285 employees in Buffalo, New York as part of major restructuring

April 17, 2024
Don't Miss

Trump says China’s Xi ‘hard to make a deal with’ amid trade dispute | Donald Trump News

By i2wtcJune 4, 20250

Growing strains in US-China relations over implementation of agreement to roll back tariffs and trade…

Donald Trump’s 50% steel and aluminium tariffs take effect | Business and Economy News

June 4, 2025

The Take: Why is Trump cracking down on Chinese students? | Education News

June 4, 2025

Chinese couple charged with smuggling toxic fungus into US | Science and Technology News

June 4, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to NabkaNews, your go-to source for the latest updates and insights on technology, business, and news from around the world, with a focus on the USA, Pakistan, and India.

At NabkaNews, we understand the importance of staying informed in today’s fast-paced world. Our mission is to provide you with accurate, relevant, and engaging content that keeps you up-to-date with the latest developments in technology, business trends, and news events.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Trump firing of Fed’s Lisa Cook case set for January

November 12, 2025

WNBA Las Vegas Aces’ Becky Hammon says league may need new leadership

November 12, 2025

AI startup Code Metal raises $36 million in funding round led by Accel

November 12, 2025
Most Popular

Rescue efforts continue after mountain torrents hit NW China’s Gansu-Xinhua

August 10, 2025

Elon Musk reaches agreement in China for self-driving Tesla

April 29, 2024

2025 World Humanoid Robot Games showcase cutting-edge tech-Xinhua

August 15, 2025
© 2025 nabkanews. Designed by nabkanews.
  • Home
  • About NabkaNews
  • Advertise with NabkaNews
  • DMCA Policy
  • Privacy Policy
  • Terms of Use
  • Contact us

Type above and press Enter to search. Press Esc to cancel.