¡¾·ì϶¹«¸æ¡¿Web ²¿ÊðÔ¶³Ì´úÂëÖ´Ðзì϶ (CVE-2025-53772)

°ä²¼¹¦·ò 2025-09-04

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Web ²¿ÊðÔ¶³Ì´úÂëÖ´Ðзì϶

CVE   ID

CVE-2025-53772

·ì϶ÀàÐÍ

RCE

·¢ÏÖ¹¦·ò

2025-09-04

·ì϶ÆÀ·Ö

8.8

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Microsoft Web Deploy£¨msdeploy£©ÊÇÒ»¿îÓÃÓÚÔÚWeb·þÎñÆ÷ÉϽøÐÐÀûÓ÷¨Ê½ºÍÅäÖò¿ÊðµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£ËüÖ§³Öͨ¹ýHTTP(S)¶Ëµã£¨msdeploy.axd£©»òWeb Deploy Agent·þÎñ£¨msdeployagentservice£©½øÐÐÔ¶³Ì²¿Ê𡣡£¡£¡£¡£¡£Web DeployÔÊÐíÓû§Í¬²½Îļþ¡¢ÍøÕ¾¡¢Ö¤Êé¡¢Êý¾Ý¿âµÈ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬£¬²¢Ö§³Ö´´½¨ºÍÀûÓò¿Êð°ü¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ß¿í·ºÓÃÓÚ½«WebÀûÓ÷¨Ê½¡¢IISÅäÖü°ÆäËû×ÊÔ´´ò°ü²¢Ç¨áãµ½Ö¸±ê»·¾³£¬£¬£¬£¬£¬£¬£¬£¬ÓµÓи߽ýÝÐÔºÍÀ©´óÐÔ¡£¡£¡£¡£¡£¡£


2025Äê9ÔÂ4ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½Ò»¸öÓ°ÏìMicrosoft Web DeployµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶£¬£¬£¬£¬£¬£¬£¬£¬´æÔÚÓÚmsdeploy.axdºÍmsdeployagentservice¶Ëµã¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚWeb Deploy·þÎñÔÚ´¦ÖÃHTTPÍ·²¿Êý¾Ýʱ£¬£¬£¬£¬£¬£¬£¬£¬Î´°²È«µØ·´ÐòÁл¯Base64ºÍGZip½âÂëºóµÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâÒªÇóÍ·£¨ÈçMSDeploy.SyncOptions£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÚWeb²¿Êð¹ý³ÌÖÐÀûÓø÷ì϶ִÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔ¶³ÌÖ´ÐÐϵͳºÅÁî²¢»ñÈ¡·þÎñÆ÷½ÚÔìȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬·ì϶ÆÀ·Ö8.8·Ö£¬£¬£¬£¬£¬£¬£¬£¬·ì϶¼¶±ð¸ßΣ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°ÏìÁìÓò


Microsoft Web Deploy 4.0 < 10.0.2001


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


ÒѰ䲼½¨¸´°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬Ç뽫Microsoft Web DeployÉý¼¶ÖÁ10.0.2001»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://www.microsoft.com/en-us/download/details.aspx?id=106070


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬£¬£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬£¬£¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬£¬£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://hawktrace.com/blog/cve-2025-53772
https://nvd.nist.gov/vuln/detail/CVE-2025-53772
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53772