CVE-2025-33053

HIGH KEV LAB

CVE-2025-33053 Exploit via Malicious .URL File and WebDAV

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2025-33053 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 10, 2025. EIP tracks 6 public exploits from researchers including DevBuiHieu, 4n4s4zi, kra1t0, including a Metasploit module exploits/windows/fileformat/unc_url_cve_2025_33053.

AI-analyzed exploit summary This repository provides scripts to deploy a WebDAV server and generate malicious `.url` shortcut files for phishing or lateral movement. The PoC leverages CVE-2025-33053 to trick victims into connecting to a malicious WebDAV server.

Description

External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

Exploits (6)

nomisec WORKING POC 64 stars
by DevBuiHieu · client-side
https://github.com/DevBuiHieu/CVE-2025-33053-Proof-Of-Concept

This repository provides scripts to deploy a WebDAV server and generate malicious `.url` shortcut files for phishing or lateral movement. The PoC leverages CVE-2025-33053 to trick victims into connecting to a malicious WebDAV server.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Windows systems with vulnerable `.url` file handling
No auth needed
Prerequisites: Ubuntu 20.04 or newer · Root privileges · Python 3.x · Apache2
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by 4n4s4zi · client-side
https://github.com/4n4s4zi/CVE-2025-33053_PoC

This PoC exploits CVE-2025-33053 by leveraging a .url file to redirect Windows clients to a malicious WebDAV server, where a fake 'route.exe' binary is executed via DLL hijacking when 'iediagcmd.exe' is launched. The setup script automates the creation of a WebDAV server to host the malicious payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Windows (via Internet Explorer diagnostics executable 'iediagcmd.exe')
No auth needed
Prerequisites: Linux host for WebDAV server · Windows client to open the malicious .url file · Malicious 'route.exe' payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by kra1t0 · poc
https://github.com/kra1t0/CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept

This repository contains a proof-of-concept exploit for CVE-2025-33053, demonstrating how a malicious `.url` file can be used to execute arbitrary code via WebDAV. The PoC includes a decoy PDF and simulates C2 behavior without actual malicious payloads.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Windows 10 (1809 – 22H2), Windows 11 (21H2 – 23H2), Windows Server 2016 / 2019 / 2022
No auth needed
Prerequisites: WebClient service enabled · User interaction to open the `.url` file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by TheTorjanCaptain · poc
https://github.com/TheTorjanCaptain/CVE-2025-33053-Checker-PoC

This repository contains a legitimate PoC and checker for CVE-2025-33053, a WebDAV-based RCE vulnerability in Windows systems. The PoC simulates a WebDAV server to detect PROPFIND requests, while the checker verifies system vulnerability via WebClient service and UNC path handling.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Windows systems with WebClient service enabled
No auth needed
Prerequisites: WebClient service running on target · UNC path resolution enabled · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Cyberw1ng · poc
https://github.com/Cyberw1ng/CVE-2025-33053-POC

This repository contains a proof-of-concept exploit for CVE-2025-33053, demonstrating how a malicious `.url` file can be used to execute arbitrary code via WebDAV. The PoC includes a decoy PDF and simulates C2 behavior without actual malicious payloads.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Windows 10 (1809 – 22H2), Windows 11 (21H2 – 23H2), Windows Server 2016 / 2019 / 2022
No auth needed
Prerequisites: WebClient service enabled · User interaction to open the `.url` file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Alexandra Gofman, David Driker, Dev Bui Hieu · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/unc_url_cve_2025_33053.rb

This Metasploit module exploits CVE-2025-33053 by generating a malicious .URL file that triggers unintended behavior via a trusted LOLBAS binary, optionally hosting a payload on a WebDAV directory for remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Windows (generic)
No auth needed
Prerequisites: Victim interaction to open the malicious .URL file · Network access to the attacker's SMB/WebDAV server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.5028
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2025-06-10
VulnCheck KEV 2025-06-10
ENISA EUVD EUVD-2025-17721
CWE
CWE-73
Status published
Products (17)
microsoft/windows_10_1507 < 10.0.10240.21034 (2 CPE variants)
microsoft/windows_10_1607 < 10.0.14393.8148 (2 CPE variants)
microsoft/windows_10_1809 < 10.0.17763.7434 (2 CPE variants)
microsoft/windows_10_21h2 < 10.0.19044.5965 (3 CPE variants)
microsoft/windows_10_22h2 < 10.0.19045.5965 (3 CPE variants)
microsoft/windows_11_22h2 < 10.0.22621.5472 (2 CPE variants)
microsoft/windows_11_23h2 < 10.0.22631.5472 (2 CPE variants)
microsoft/windows_11_24h2 < 10.0.26100.4270 (2 CPE variants)
microsoft/windows_server_2008 (2 CPE variants)
microsoft/windows_server_2008 r2 sp1
... and 7 more
Published Jun 10, 2025
KEV Added Jun 10, 2025
Tracked Since Feb 18, 2026