PT-2025-32852 · Microsoft · Web Deploy
Batuhan Er
+1
·
Published
2025-08-12
·
Updated
2026-02-13
·
CVE-2025-53772
CVSS v2.0
9.0
High
| AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft IIS Web Deploy versions prior to August 2025 PatchDay
Description
An issue exists in Microsoft Web Deploy where unsafe deserialization of HTTP header contents allows an authenticated attacker to execute code remotely. The vulnerability resides in the
msdeployagentservice and msdeploy.axd endpoints. Specifically, the vulnerability involves insecure deserialization of GZip and Base64 encoded headers. Successful exploitation requires only low privileges and no user interaction. A proof-of-concept (PoC) exploit is publicly available. The vulnerability allows an authorized attacker to execute code over a network.Recommendations
Apply security updates released on or after the August 2025 PatchDay.
Restrict access to the
msdeploy.axd and msdeployagentservice endpoints.Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Web Deploy