CVE-2025-53772 is a deserialization of untrusted data vulnerability in Web Deploy. According to the provided content, Web Deploy improperly deserializes attacker-controlled data, allowing an authorized attacker to execute code over a network. The issue is consistent with unsafe handling of serialized input in a network-reachable context, where crafted serialized data can trigger unintended object construction or gadget-chain execution during deserialization, resulting in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a standalone Python exploit for CVE-2025-53772, a remote code execution vulnerability in Microsoft Web Deploy (msdeploy) versions prior to 10.0.2001. The exploit targets two main endpoints: /MSDEPLOYAGENTSERVICE (port 80, NTLM authentication) and /msdeploy.axd (port 8172, Basic authentication). The core exploit (CVE-2025-53772.py) crafts a malicious .NET BinaryFormatter payload, which is base64-encoded and sent in the MSDeploy.SyncOptions HTTP header. The payload can be customized to execute arbitrary commands on the target Windows server, such as creating proof files or launching calc.exe. The exploit requires valid credentials and can be used to verify code execution by checking for created files on the target. The repository includes a README with detailed usage instructions, affected endpoints, mitigation steps, and troubleshooting tips. The code is operational and suitable for authorized security testing.
This repository provides a Proof-of-Concept (PoC) exploit for CVE-2025-53772, a critical remote code execution vulnerability in Microsoft IIS WebDeploy due to unsafe deserialization. The main exploit logic is implemented in 'poc.cs', a C# program that crafts a malicious .NET BinaryFormatter serialized object. This object, when deserialized by a vulnerable WebDeploy instance, triggers arbitrary command execution on the server. The payload is customizable and can be set to execute system commands, exfiltrate system information to a webhook, or establish a reverse shell by downloading and executing a remote PowerShell script. The repository includes a GitHub Actions workflow for automated compilation and payload generation, and a README with detailed usage instructions, payload customization examples, and mitigation advice. The exploit is a POC and requires the attacker to send the generated payload to a vulnerable IIS WebDeploy endpoint. Notable endpoints in the code include webhook.site for exfiltration and a sample reverse shell server. The repository is structured with a single exploit source file, a workflow for automation, and comprehensive documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.