You can compromise the system if the updates are not requested using httpS but http.
# Check if the network uses a non-SSL WSUS update by running the following :reg query HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate /v WUServer# If you get a reply such as:HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate WUServer REG_SZ http://xxxx-updxx.corp.internal.com:8535# and if this returns 1 :reg query HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU /v UseWUServer# this is exploitable. If the last registry is equals to 0, then, the WSUS entry will be ignored.