Story perspectives
Microsoft's Update Disrupts Hotpatching, Exposes Servers to Vulnerability
11/4/2025
1 of 1
Story summary
- Microsoft's security update for Windows Server Update Services disrupted hotpatching on some Windows Server 2025 systems, exposing enterprise environments to the remote code execution flaw CVE-2025-59287.
- Affected servers must rely on traditional updates that require reboots until a baseline update in January 2026 restores hotpatching.
- Microsoft released fix KB5070893 to address the vulnerability without impacting hotpatch functionality.
- The Cybersecurity and Infrastructure Security Agency (CISA) has advised U.S. agencies to secure their systems against this vulnerability.
