Microsoft

Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical remote code execution (RCE) vulnerability in Microsoft’s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security updates through Intune.

The flaw stems from the tool connecting to dropped Azure Blob storage accounts that attackers could register and control.​

How the Vulnerability Works

The vulnerability exists in version 1.0 of the Update Health Tools, which uses Azure Blob storage accounts following a predictable naming pattern (payloadprod0 through payloadprod15.blob.core.windows.net) to fetch configuration files and commands.

Eye Security researchers found that Microsoft had left 10 of the 15 storage accounts unregistered and unused.

After registering these abandoned endpoints, the researchers observed over 544,000 HTTP requests within seven days from nearly 10,000 unique Azure tenants worldwide.

The tool’s uhssvc.exe service, located at C:\Program Files\Microsoft Update Health Tools, was actively resolving these domains across multiple enterprise environments.​

uhssvc.exe file

The critical issue lies in the tool’s “ExecuteTool” action, which allows execution of Microsoft-signed binaries.

By crafting malicious JSON payloads that point to legitimate Windows executables such as explorer.exe, attackers can achieve arbitrary code execution on vulnerable systems.​

The newer version 1.1 implements a proper web service at devicelistenerprod.microsoft.com, though backward-compatibility options could still expose systems.​

Eye Security reported the vulnerability to Microsoft on July 7, 2025, and Microsoft confirmed the behavior on July 17.

Hashicorp researchers transferred ownership of all compromised storage accounts back to Microsoft on July 18, 2025, effectively closing the attack vector.​

Organizations should ensure they are running the latest version of Update Health Tools and verify no legacy configurations remain enabled.

Security teams should monitor for unusual network traffic to Azure Blob storage endpoints from update services.​

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago