You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-53772
About this tag
CVE-2025-53772 is a deserialization vulnerability in Microsoft Web Deploy (MSDeploy) that allows an authenticated user who can reach the Web Deploy endpoint to cause remote code execution on the target server. Discussions on WindowsForum highlight the urgency of applying Microsoft's security update, especially for servers exposing the Web Deployment Handler at port 8172. The vulnerability was disclosed during a Patch Tuesday cycle that saw 1,224 new vulnerabilities, underscoring the need for rapid patching. Administrators are advised to patch immediately or restrict network access to the endpoint as a temporary mitigation.
Cyble’s latest weekly vulnerability roundup paints a stark picture: this Patch Tuesday cycle produced a torrent of disclosures — 1,224 new vulnerabilities tracked in seven days — and a rapidly shrinking window for defenders as publicly shared proofs‑of‑concept (PoCs) proliferate.
Background...
TL;DR — Microsoft has published a security advisory for CVE-2025-53772: a deserialization vulnerability in Web Deploy (msdeploy) that can allow an authenticated (authorized) user who can reach the Web Deploy endpoint to cause remote code execution on the target server. If you run Web Deploy (the...