Deserialization Vulnerability in Web Deploy by Microsoft
CVE-2025-53772

8.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 August 2025

Badges

πŸ”₯ Trending nowπŸ₯‡ Trended No. 1πŸ“ˆ TrendedπŸ“ˆ Score: 4,670

What is CVE-2025-53772?

CVE-2025-53772 is a notable vulnerability found in Microsoft's Web Deploy, a tool widely utilized for deploying web applications and services. This vulnerability arises from the improper handling of untrusted data during the deserialization process, which can allow an authorized attacker to execute arbitrary code over a network. If exploited, this vulnerability poses a serious risk to organizations as it may enable attackers to take control of affected systems, manipulate sensitive web applications, and potentially compromise network integrity. The impact is particularly alarming for businesses that rely on Web Deploy to manage their web infrastructure, as successful exploitation could lead to significant operational disruptions and data exposure.

Potential impact of CVE-2025-53772

  1. Remote Code Execution: The primary risk associated with CVE-2025-53772 is the ability for an attacker to execute arbitrary code on a server, which could compromise server integrity and lead to unauthorized actions being performed.

  2. System Compromise: By exploiting this vulnerability, attackers can potentially gain complete control over affected systems, allowing them to access sensitive information, manipulate data, or deploy additional malicious software.

  3. Operational Disruption: Organizations may face significant downtime and resource allocation challenges if the vulnerability is exploited, as it could require immediate mitigation actions, including system restorations and security overhauls, negatively impacting business operations.

Affected Version(s)

Web Deploy 4.0 Unknown 10.0.2000 < 10.0.2001

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ₯‡

    Vulnerability reached the number 1 worldwide trending spot

  • πŸ“ˆ

    Vulnerability started trending

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53772 : Deserialization Vulnerability in Web Deploy by Microsoft