Spun up a WSUS instance on a W2k25. (Build 10.0.26100 - unpatched since aug)
Interestingly Microsoft.UpdateServices.Internal.Authorization.EncryptionHelper.DecryptData did not use the vulnerable BinaryFormatter class but the XmlSerializer.
#KB5070881 is not installed.
Spun up a WSUS instance on a W2k25. (Build 10.0.26100 - unpatched since aug)
Interestingly Microsoft.UpdateServices.Internal.Authorization.EncryptionHelper.DecryptData did not use the vulnerable BinaryFormatter class but the XmlSerializer.
#KB5070881 is not installed.
scholarspace.manoa.hawaii.edu/items/88cd00...
scholarspace.manoa.hawaii.edu/items/88cd00...