References https://nvd.nist.gov/vuln/detail/CVE-2025-53772 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53772 https://easy2patch.medium.com/critical-vulnerability-in-microsoft-web-deploy-remote-code-execution-with-low-privileges-44234f8fd43f https://rewterz.com/threat-advisory/microsoft-iis-web-deploy-rce-vulnerability https://www.threads.com/@vlab_ict/post/DOKUeETCefL https://its.hku.hk/security-alerts/microsoft-iis-web-deploy-vulnerability-let-attackers-execute-remote-code/ https://github.com/sailay1996/CVE-2025-53772 https://hawktrace.com/blog/cve-2025-53772/ https://javascript.plainenglish.io/cve-2025-53772-the-silent-risk-in-microsoft-web-deploy-18fa67f02e15 https://www.sentinelone.com/vulnerability-database/cve-2025-53772/
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoCCVE-2026-33626: LMDeploy - Server-Side Request Forgery用友NC /portal/pt/M0dUlE/redeploy SQL 注入漏洞PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts DisclosurePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page DisclosurePoCsharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata DisclosurePoCsharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages Disclosure