{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftweb_deploy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:web_deploy:*:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:web_deploy_4.0:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2025-53772"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Web Deploy (\u003c 10.0.2001)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","deserialization","cve-2025-53772","iis","web-deploy"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMicrosoft Web Deploy (msdeploy) versions prior to 10.0.2001 are vulnerable to remote code execution (RCE) due to insecure deserialization of untrusted data (CWE-502). The vulnerability resides in the processing of the 'MSDeploy.SyncOptions' HTTP header, which is passed to a .NET 'BinaryFormatter' for deserialization. By providing a specially crafted serialized object, an attacker can leverage a gadget chain to trigger arbitrary code execution under the context of the service account.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is exploitable via two primary endpoints: the Web Deploy Agent Service ('/MSDEPLOYAGENTSERVICE') on port 80 using NTLM authentication, and the WMSvc service ('/msdeploy.axd') on port 8172 using Basic authentication. Public proof-of-concept code is available, significantly increasing the risk of exploitation. Defenders should verify the version of 'msdeploy.exe' on their IIS servers and prioritize patching to 10.0.2001 or higher.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify IIS servers exposing the Web Deploy Agent Service (port 80) or WMSvc (port 8172).\u003c/li\u003e\n\u003cli\u003eAttacker obtains or identifies low-privilege credentials valid for the targeted service authentication (NTLM or Basic).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a serialized .NET payload designed to trigger a TypeConfuseDelegate gadget chain.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP POST request to the target endpoint, inserting the malicious payload into the 'MSDeploy.SyncOptions' header.\u003c/li\u003e\n\u003cli\u003eThe target application's 'BinaryFormatter.Deserialize()' method processes the header, instantiating the malicious object graph.\u003c/li\u003e\n\u003cli\u003eThe gadget chain execution causes the application process to invoke 'Process.Start' to run arbitrary system commands (e.g., 'cmd.exe').\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution, typically resulting in the creation of persistence mechanisms or the execution of further payloads.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary code on the server, potentially leading to full system compromise. Given the service's role in deployment and administration, this can facilitate lateral movement, exfiltration of application data, or the deployment of ransomware. The vulnerability has a CVSS 8.8 score and is actively being targeted with public exploit code.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Microsoft Web Deploy to version 10.0.2001 or later immediately across all IIS environments.\u003c/li\u003e\n\u003cli\u003eDisable the Web Deploy Agent Service and WMSvc if they are not strictly required for business operations.\u003c/li\u003e\n\u003cli\u003eApply the detection rules below to identify exploitation attempts targeting the 'MSDeploy.SyncOptions' header.\u003c/li\u003e\n\u003cli\u003eRestrict network access to port 80/8172 endpoints via firewalls to only authorized management subnets.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual 'cmd.exe' or 'powershell.exe' process spawns originating from the 'msdeploy.exe' process or related IIS worker processes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-06T02:25:11Z","date_published":"2026-09-06T02:25:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-53772/","summary":"An unauthenticated or low-privilege attacker can achieve remote code execution in Microsoft Web Deploy versions prior to 10.0.2001 by exploiting insecure deserialization of the 'MSDeploy.SyncOptions' HTTP header.","title":"Remote Code Execution in Microsoft Web Deploy via CVE-2025-53772","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-53772/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:microsoft:web_deploy:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}