Close Menu
Nabka News
  • Home
  • News
  • Business
  • China
  • India
  • Pakistan
  • Political
  • Tech
  • Trend
  • USA
  • Sports

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Guiyang-Pingtang Expressway to operate in southwest China’s Guizhou-Xinhua

December 25, 2025

UN expert flags ‘serious risk’ to Bushra Bibi’s well-being

December 25, 2025

Northwest China’s Xi’an-Yan’an high-speed railway set to open on Dec. 26-Xinhua

December 25, 2025
Facebook X (Twitter) Instagram
  • Home
  • About NabkaNews
  • Advertise with NabkaNews
  • DMCA Policy
  • Privacy Policy
  • Terms of Use
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Nabka News
  • Home
  • News
  • Business
  • China
  • India
  • Pakistan
  • Political
  • Tech
  • Trend
  • USA
  • Sports
Nabka News
Home » Windows server vulnerability identified by PKCERT
Pakistan

Windows server vulnerability identified by PKCERT

i2wtcBy i2wtcNovember 12, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp Copy Link
Follow Us
Google News Flipboard Threads
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


Pakistan’s national cyber-incident response body, Pakistan Computer Emergency Response Team, has issued a critical security advisory concerning a high-risk vulnerability in Microsoft Windows Server Update Services, the software used by many organisations for patch management of Windows servers.

Microsoft Windows Server Update Services (WSUS) is the central system that large organisations (like government offices or major companies) use to manage, distribute, and install updates (patches) across their entire network of computers. The exploit works by unsafe deserialisation of the WSUS Authorisation Cookie: the attacker sends a corrupted permission note, like a cookie, to the server that tricks the system into executing the attacker’s own code instead of ignoring the bad input.

The flaw allows for remote control execution (RCE) of a compromised system, which means that an attacker can remotely run their own malicious programs or commands on the vulnerable server from anywhere in the world, “leading to complete server compromise,” according to the Pakistan Computer Emergency Response Team (PKCERT) advisory. The attacker is “unauthenticated”, meaning they require no username or password to exploit this vulnerability, and PKCERT has said that this flaw is being “actively exploited in the wild.”

How does this happen?

Serialising is when a web application converts complex data, like your session information or website permissions, into a compact format for easy sending and storage. When the information needs to be used again, the application then deserialises the information.

“Unsafe deserialisation” happens when a program blindly trusts data it’s deserialising, meaning it doesn’t check whether that data has been tampered with. If an attacker can modify that data —a cookie, token, or hidden field — and the server deserialises it without verification, the attacker can inject malicious code or commands that run on the server’s side.

In this case, the WSUS Authorisation Cookie (a piece of data WSUS uses to know who’s connecting and what they can do) is not properly validated before being deserialised. Since WSUS servers manage updates across entire networks, a compromised WSUS host could push infected updates to thousands of connected machines, spreading malware or ransomware silently across corporate and government systems, stealing and transferring authentication and network data, or take full system control of all machines on a network (they can run any code they want).

According to PKCERT, they have given this vulnerability score on the Common Vulnerability Scoring System a value of 9.8, meaning a critical threat to national public and private systems. Any organisation is at risk if they have Windows systems that are not running the most updated versions, as well as systems that are publicly accessible, among others.

Combating the exploit

PKCERT has issued a few solutions to the problem. They recommend applying Microsoft’s October 2025 out-of-band patch (a patch that was released outside of the normal patch cycle), temporarily blocking affected Internet ports, which act as doorways on your computer that let specific types of online traffic go in and out, and strengthening server security, like ensuring WSUS servers aren’t exposed to the public internet.

They also call on organisations to be more vigilant with suspicious cyber activity and to track unauthorised server access to ensure the security of their organisations.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp Copy Link
i2wtc
  • Website

Related Posts

Pakistan

UN expert flags ‘serious risk’ to Bushra Bibi’s well-being

December 25, 2025
Pakistan

K-P launches comprehensive disaster management plan to tackle climate risks

December 25, 2025
Pakistan

Sindh launches digital system to track medicines, prevent illegal sales in public hospitals

December 24, 2025
Pakistan

TTAP agrees to dialogue with government, calls for new charter

December 24, 2025
Pakistan

Pakistan shifts from stabilisation to export-led growth, says finance minister

December 24, 2025
Pakistan

PIA to be run by Arif Habib-led consortium by April 2026

December 24, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

House Republicans unveil aid bill for Israel, Ukraine ahead of weekend House vote

April 17, 2024

Prime Minister Johnson presses forward with Ukraine aid bill despite pressure from hardliners

April 17, 2024

Justin Verlander makes season debut against Nationals

April 17, 2024

Tesla lays off 285 employees in Buffalo, New York as part of major restructuring

April 17, 2024
Don't Miss

Trump says China’s Xi ‘hard to make a deal with’ amid trade dispute | Donald Trump News

By i2wtcJune 4, 20250

Growing strains in US-China relations over implementation of agreement to roll back tariffs and trade…

Donald Trump’s 50% steel and aluminium tariffs take effect | Business and Economy News

June 4, 2025

The Take: Why is Trump cracking down on Chinese students? | Education News

June 4, 2025

Chinese couple charged with smuggling toxic fungus into US | Science and Technology News

June 4, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to NabkaNews, your go-to source for the latest updates and insights on technology, business, and news from around the world, with a focus on the USA, Pakistan, and India.

At NabkaNews, we understand the importance of staying informed in today’s fast-paced world. Our mission is to provide you with accurate, relevant, and engaging content that keeps you up-to-date with the latest developments in technology, business trends, and news events.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Guiyang-Pingtang Expressway to operate in southwest China’s Guizhou-Xinhua

December 25, 2025

UN expert flags ‘serious risk’ to Bushra Bibi’s well-being

December 25, 2025

Northwest China’s Xi’an-Yan’an high-speed railway set to open on Dec. 26-Xinhua

December 25, 2025
Most Popular

Treasure trove discovered in ancient shipwreck 5,000 feet below sea level in South China Sea

June 14, 2024

China’s Belt and Road Initiative a plus, the rest so-so on Hong Kong-Chiang Mai journey

June 15, 2024

The collision between Chinese and Philippine vessels is just the latest in a series of clashes in the South China Sea.

June 17, 2024
© 2025 nabkanews. Designed by nabkanews.
  • Home
  • About NabkaNews
  • Advertise with NabkaNews
  • DMCA Policy
  • Privacy Policy
  • Terms of Use
  • Contact us

Type above and press Enter to search. Press Esc to cancel.