CVE-2025-53772 is a critical deserialization of untrusted data vulnerability affecting Microsoft Web Deploy 4.0. An authorized attacker can exploit this flaw over a network to achieve remote code execution. With a CVSS score of 8.8 (High), this vulnerability poses a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While not currently listed in KEV or having public exploit code in Metasploit, Nuclei, or ExploitDB, its recent mention in a BleepingComputer article and community discussion indicate emerging awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.2001CPE matchmatch criteria | cpe:2.3:a:microsoft:web_deploy_4.0:*:*:*:*:*:*:*:* | ||
>= 10.0.2000, < 10.0.2001CPE match | cpe:2.3:a:microsoft:web_deploy_4.0:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.