Close Menu
Nabka News
  • Home
  • News
  • Business
  • China
  • India
  • Pakistan
  • Political
  • Tech
  • Trend
  • USA
  • Sports

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Iran warns of strikes on US-linked universities in region after campus bombings

March 30, 2026

Trump warns US could ‘take the oil in Iran’ as Mideast war escalates

March 30, 2026

Ningbo-Zhoushan Port in east China’s Zhejiang records rising container throughput -Xinhua

March 30, 2026
Facebook X (Twitter) Instagram
  • Home
  • About NabkaNews
  • Advertise with NabkaNews
  • DMCA Policy
  • Privacy Policy
  • Terms of Use
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Nabka News
  • Home
  • News
  • Business
  • China
  • India
  • Pakistan
  • Political
  • Tech
  • Trend
  • USA
  • Sports
Nabka News
Home » Windows server vulnerability identified by PKCERT
Pakistan

Windows server vulnerability identified by PKCERT

i2wtcBy i2wtcNovember 12, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp Copy Link
Follow Us
Google News Flipboard Threads
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


Pakistan’s national cyber-incident response body, Pakistan Computer Emergency Response Team, has issued a critical security advisory concerning a high-risk vulnerability in Microsoft Windows Server Update Services, the software used by many organisations for patch management of Windows servers.

Microsoft Windows Server Update Services (WSUS) is the central system that large organisations (like government offices or major companies) use to manage, distribute, and install updates (patches) across their entire network of computers. The exploit works by unsafe deserialisation of the WSUS Authorisation Cookie: the attacker sends a corrupted permission note, like a cookie, to the server that tricks the system into executing the attacker’s own code instead of ignoring the bad input.

The flaw allows for remote control execution (RCE) of a compromised system, which means that an attacker can remotely run their own malicious programs or commands on the vulnerable server from anywhere in the world, “leading to complete server compromise,” according to the Pakistan Computer Emergency Response Team (PKCERT) advisory. The attacker is “unauthenticated”, meaning they require no username or password to exploit this vulnerability, and PKCERT has said that this flaw is being “actively exploited in the wild.”

How does this happen?

Serialising is when a web application converts complex data, like your session information or website permissions, into a compact format for easy sending and storage. When the information needs to be used again, the application then deserialises the information.

“Unsafe deserialisation” happens when a program blindly trusts data it’s deserialising, meaning it doesn’t check whether that data has been tampered with. If an attacker can modify that data —a cookie, token, or hidden field — and the server deserialises it without verification, the attacker can inject malicious code or commands that run on the server’s side.

In this case, the WSUS Authorisation Cookie (a piece of data WSUS uses to know who’s connecting and what they can do) is not properly validated before being deserialised. Since WSUS servers manage updates across entire networks, a compromised WSUS host could push infected updates to thousands of connected machines, spreading malware or ransomware silently across corporate and government systems, stealing and transferring authentication and network data, or take full system control of all machines on a network (they can run any code they want).

According to PKCERT, they have given this vulnerability score on the Common Vulnerability Scoring System a value of 9.8, meaning a critical threat to national public and private systems. Any organisation is at risk if they have Windows systems that are not running the most updated versions, as well as systems that are publicly accessible, among others.

Combating the exploit

PKCERT has issued a few solutions to the problem. They recommend applying Microsoft’s October 2025 out-of-band patch (a patch that was released outside of the normal patch cycle), temporarily blocking affected Internet ports, which act as doorways on your computer that let specific types of online traffic go in and out, and strengthening server security, like ensuring WSUS servers aren’t exposed to the public internet.

They also call on organisations to be more vigilant with suspicious cyber activity and to track unauthorised server access to ensure the security of their organisations.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp Copy Link
i2wtc
  • Website

Related Posts

Pakistan

Iran warns of strikes on US-linked universities in region after campus bombings

March 30, 2026
Pakistan

Pope Leo says God rejects prayers of leaders who wage wars

March 30, 2026
Pakistan

PIA restarts Islamabad-London service with inaugural flight

March 30, 2026
Pakistan

Karachi police detain six Sindh nationalist leaders outside press club

March 29, 2026
Pakistan

Security forces defuse 8 IEDs on Quetta–Karachi highway, averting major attack

March 29, 2026
Pakistan

Dar says Turkiye, Saudi Arabia, Egypt back dialogue as only way to ‘permanently end’ US-Iran war

March 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

House Republicans unveil aid bill for Israel, Ukraine ahead of weekend House vote

April 17, 2024

Prime Minister Johnson presses forward with Ukraine aid bill despite pressure from hardliners

April 17, 2024

Justin Verlander makes season debut against Nationals

April 17, 2024

Tesla lays off 285 employees in Buffalo, New York as part of major restructuring

April 17, 2024
Don't Miss

Trump says China’s Xi ‘hard to make a deal with’ amid trade dispute | Donald Trump News

By i2wtcJune 4, 20250

Growing strains in US-China relations over implementation of agreement to roll back tariffs and trade…

Donald Trump’s 50% steel and aluminium tariffs take effect | Business and Economy News

June 4, 2025

The Take: Why is Trump cracking down on Chinese students? | Education News

June 4, 2025

Chinese couple charged with smuggling toxic fungus into US | Science and Technology News

June 4, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to NabkaNews, your go-to source for the latest updates and insights on technology, business, and news from around the world, with a focus on the USA, Pakistan, and India.

At NabkaNews, we understand the importance of staying informed in today’s fast-paced world. Our mission is to provide you with accurate, relevant, and engaging content that keeps you up-to-date with the latest developments in technology, business trends, and news events.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Iran warns of strikes on US-linked universities in region after campus bombings

March 30, 2026

Trump warns US could ‘take the oil in Iran’ as Mideast war escalates

March 30, 2026

Ningbo-Zhoushan Port in east China’s Zhejiang records rising container throughput -Xinhua

March 30, 2026
Most Popular

Philippine Coast Guard says China has parked ‘monster ship’ in South China Sea

July 6, 2024

China, Belarusian militaries conduct joint anti-terrorism drills

July 7, 2024

Australia accuses China-backed hackers of infiltrating government networks

July 9, 2024
© 2026 nabkanews. Designed by nabkanews.
  • Home
  • About NabkaNews
  • Advertise with NabkaNews
  • DMCA Policy
  • Privacy Policy
  • Terms of Use
  • Contact us

Type above and press Enter to search. Press Esc to cancel.