Description
This module exploits deserialization vulnerability in legacy serialization mechanism in Windows Server Update Services (WSUS). The vulnerability allows unauthenticated attacker to create specially crafted event, which triggers unsafe deserialization upon server synchronization. The module does not require any other options and upon successful exploitation, the payload is executed in context of administrator.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/http/wsus_deserialization_rcemsf undefined(wsus_deserialization_rce) > show actions ...actions...msf undefined(wsus_deserialization_rce) > set ACTION < action-name >msf undefined(wsus_deserialization_rce) > show options ...show and set options...msf undefined(wsus_deserialization_rce) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub