Potential Exploitation of RCE Vulnerability CVE-2025-33053
Detects potential exploitation of remote code execution vulnerability CVE-2025-33053 which involves unauthorized code execution via WebDAV through external control of file names or paths. The exploit abuses legitimate utilities like iediagcmd.exe or CustomShellHost.exe by manipulating their working directories to point to attacker-controlled WebDAV servers, causing them to execute malicious executables (like route.exe) from the WebDAV path instead of legitimate system binaries through Process.Start() search order manipulation.
Detection logic
selection_parent
ParentImage:
- C:\Program Files\internet explorer\iediagcmd.exe
- C:\Windows\System32\CustomShellHost.exeselection_child_current_dir
- CurrentDirectory|startswith: \\\\
- CurrentDirectory|contains: \DavWWWRoot\
- Image|contains: \DavWWWRoot\
- Image|startswith: \\\\selection_child_img
Image|endswith:
- \route.exe
- \netsh.exe
- \makecab.exe
- \dxdiag.exe
- \ipconfig.exe
- \explorer.exefilter_main_system
Image|startswith:
- C:\Windows\System32\
- C:\Windows\SysWOW64\Condition
all of selection_* and not 1 of filter_main_*Raw YAML
title: Potential Exploitation of RCE Vulnerability CVE-2025-33053
id: abe06362-a5b9-4371-8724-ebd00cd48a04
related:
- id: 9a2d8b3e-f5a1-4c68-9e21-7d9e1cf8a123
type: similar
- id: 04fc4b22-91a6-495a-879d-0144fec5ec03
type: similar
status: experimental
description: |
Detects potential exploitation of remote code execution vulnerability CVE-2025-33053
which involves unauthorized code execution via WebDAV through external control of file names or paths.
The exploit abuses legitimate utilities like iediagcmd.exe or CustomShellHost.exe by manipulating
their working directories to point to attacker-controlled WebDAV servers, causing them to execute
malicious executables (like route.exe) from the WebDAV path instead of legitimate system binaries
through Process.Start() search order manipulation.
references:
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053
- https://research.checkpoint.com/2025/stealth-falcon-zero-day/
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-06-13
tags:
- attack.command-and-control
- attack.execution
- attack.stealth
- attack.t1218
- attack.lateral-movement
- attack.t1105
- detection.emerging-threats
- cve.2025-33053
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage:
- 'C:\Program Files\internet explorer\iediagcmd.exe'
- 'C:\Windows\System32\CustomShellHost.exe'
selection_child_current_dir:
- CurrentDirectory|startswith: '\\\\'
- CurrentDirectory|contains: '\DavWWWRoot\'
- Image|contains: '\DavWWWRoot\'
- Image|startswith: '\\\\'
selection_child_img:
Image|endswith:
- '\route.exe'
- '\netsh.exe'
- '\makecab.exe'
- '\dxdiag.exe'
- '\ipconfig.exe'
- '\explorer.exe'
filter_main_system:
Image|startswith:
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
condition: all of selection_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: highFalse positives
- Unknown
References
Related rules
Similar rules
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
highwindows · Shares T1218, T1105
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
highwindows · Shares T1218, T1105
Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
mediumwindows · Shares T1105, T1218
PowerShell MSI Install via WindowsInstaller COM From Remote Location
mediumwindows · Shares T1218, T1105