¡¾Îó²îͨ¸æ¡¿Web °²ÅÅÔ¶³Ì´úÂëÖ´ÐÐÎó²î (CVE-2025-53772)
Ðû²¼Ê±¼ä 2025-09-04Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Web °²ÅÅÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-53772 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-09-04 |
Îó²îÆÀ·Ö | 8.8 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Microsoft Web Deploy£¨msdeploy£©ÊÇÒ»¿îÓÃÓÚÔÚWeb·þÎñÆ÷ÉϾÙÐÐÓ¦ÓóÌÐòºÍÉèÖð²ÅŵŤ¾ß¡£ËüÖ§³Öͨ¹ýHTTP(S)¶Ëµã£¨msdeploy.axd£©»òWeb Deploy Agent·þÎñ£¨msdeployagentservice£©¾ÙÐÐÔ¶³Ì°²ÅÅ¡£Web DeployÔÊÐíÓû§Í¬²½Îļþ¡¢ÍøÕ¾¡¢Ö¤Êé¡¢Êý¾Ý¿âµÈ×ÊÔ´£¬²¢Ö§³Ö½¨ÉèºÍÓ¦Óð²ÅŰü¡£¸Ã¹¤¾ßÆÕ±éÓÃÓÚ½«WebÓ¦ÓóÌÐò¡¢IISÉèÖü°ÆäËû×ÊÔ´´ò°ü²¢Ç¨á㵽ĿµÄÇéÐΣ¬¾ßÓиßÎÞаÐÔºÍÀ©Õ¹ÐÔ¡£
2025Äê9ÔÂ4ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½Ò»¸öÓ°ÏìMicrosoft Web DeployµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¬±£´æÓÚmsdeploy.axdºÍmsdeployagentservice¶Ëµã¡£¸ÃÎó²îÔ´ÓÚWeb Deploy·þÎñÔÚ´¦Öóͷ£HTTPÍ·²¿Êý¾Ýʱ£¬Î´Çå¾²µØ·´ÐòÁл¯Base64ºÍGZip½âÂëºóµÄÄÚÈÝ¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóÍ·£¨ÈçMSDeploy.SyncOptions£©£¬ÔÚWeb°²ÅÅÀú³ÌÖÐʹÓøÃÎó²îÖ´ÐжñÒâ´úÂ룬´Ó¶øÔ¶³ÌÖ´ÐÐϵͳÏÂÁî²¢»ñÈ¡·þÎñÆ÷¿ØÖÆÈ¨ÏÞ£¬Îó²îÆÀ·Ö8.8·Ö£¬Îó²î¼¶±ð¸ßΣ¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://www.microsoft.com/en-us/download/details.aspx?id=106070
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ