

Microsoft IIS Web Deploy RCE Vulnerability
August 18, 2025
Hacked Cisco, Linksys, Araknis Routers See Scan Spike
August 19, 2025
Microsoft IIS Web Deploy RCE Vulnerability
August 18, 2025
Hacked Cisco, Linksys, Araknis Routers See Scan Spike
August 19, 2025Severity
High
Analysis Summary
CVE-2025-53772 CVSS:8.8
Microsoft Web Deploy could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data.
CVE-2025-53729 CVSS:7.8
Microsoft Azure File Sync could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper access control.
CVE-2025-53793 CVSS:7.5
Microsoft Azure Stack Hub could allow a local attacker to obtain sensitive information, caused by improper authentication that allows the exposure of private personal information to an unauthorized actor.
CVE-2025-53140 CVSS:7
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a use-after-free error in the Kernel Transaction Manager component.
CVE-2025-53149 CVSS:7.8
Microsoft Windows is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the Kernel Streaming WOW Thunk Service Driver component. A local authenticated attacker could exploit this vulnerability to gain elevated privileges on the system.
CVE-2025-50154 CVSS:7.5
Microsoft Windows could allow a remote attacker to conduct spoofing attacks, caused by exposure of sensitive information to an unauthorized actor in the File Explorer.
CVE-2025-25005 CVSS:6.5
Microsoft Exchange Server could allow a remote attacker to obtain sensitive information, caused by an improper input validation error.
CVE-2025-53779 CVSS:7.2
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a relative path traversal in the Kerberos component.
Impact
- Gain Access
- Code Execution
- Privilege Escalation
- Information Disclosure
Indicators of Compromise
CVE
- CVE-2025-53772
- CVE-2025-53729
- CVE-2025-53793
- CVE-2025-53140
- CVE-2025-53149
- CVE-2025-50154
- CVE-2025-25005
- CVE-2025-53779
Affected Vendors
- Microsoft
Affected Products
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server 2012
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2022
- Microsoft Windows Server 2019 (Server Core installation)
- Microsoft Windows Server 2012 (Server Core installation)
- Microsoft Windows Server 2012 R2 (Server Core installation)
- Microsoft Windows Server 2016 (Server Core installation)
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Windows Server 2025 (Server Core installation)
- Microsoft Windows 10 Version 1507
- Microsoft Windows 11 version 22H2
- Microsoft Windows 10 Version 1809
- Microsoft Windows 11 version 22H3
- Microsoft Windows 11 Version 23H2
- Microsoft Windows Server 2025 (Server Core installation) 10.0.26100.0
- Microsoft Windows Server 2025 10.0.26100.0
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Web Deploy 4.0
- Microsoft Azure File Sync
- Microsoft Azure Stack Hub 2408
- Microsoft Azure Stack Hub 2406
- Microsoft Azure Stack Hub 2501
- Microsoft Windows Server 2022 - 23H2 Edition (Server Core installation)
Remediation
Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.