Windows: Potential CVE-2025-33053 WebDAV RCE via iediagcmd.exe or CustomShellHost.exe

Flags suspicious child execution from WebDAV/UNC paths initiated by iediagcmd.exe or CustomShellHost.exe, consistent with CVE-2025-33053 exploitation.

FreeUnreviewedSigmahighv1
title: "Windows: Potential CVE-2025-33053 WebDAV RCE via iediagcmd.exe or CustomShellHost.exe"
id: a74dc046-3f36-4aa6-adc7-7ee33c05f6b8
related:
  - id: 9a2d8b3e-f5a1-4c68-9e21-7d9e1cf8a123
    type: similar
  - id: 04fc4b22-91a6-495a-879d-0144fec5ec03
    type: similar
  - id: abe06362-a5b9-4371-8724-ebd00cd48a04
    type: derived
status: experimental
description: This rule identifies process execution where iediagcmd.exe or CustomShellHost.exe starts another binary while operating from a WebDAV-related path (e.g., involving \DavWWWRoot\ or UNC paths). The behavior can indicate RCE exploitation using an attacker-controlled WebDAV server to manipulate which executable gets launched, leveraging Windows process start/search behavior. It relies on process creation telemetry, including parent image, current directory, and the spawned child image path, while excluding typical system-binary paths under System32/SysWOW64.
references:
  - https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053
  - https://research.checkpoint.com/2025/stealth-falcon-zero-day/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Exploits/CVE-2025-33053/proc_creation_win_exploit_cve_2025_33053.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-06-13
tags:
  - attack.command-and-control
  - attack.execution
  - attack.stealth
  - attack.t1218
  - attack.lateral-movement
  - attack.t1105
  - detection.emerging-threats
  - cve.2025-33053
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage:
      - C:\Program Files\internet explorer\iediagcmd.exe
      - C:\Windows\System32\CustomShellHost.exe
  selection_child_current_dir:
    - CurrentDirectory|startswith: \\\\
    - CurrentDirectory|contains: \DavWWWRoot\
    - Image|contains: \DavWWWRoot\
    - Image|startswith: \\\\
  selection_child_img:
    Image|endswith:
      - \route.exe
      - \netsh.exe
      - \makecab.exe
      - \dxdiag.exe
      - \ipconfig.exe
      - \explorer.exe
  filter_main_system:
    Image|startswith:
      - C:\Windows\System32\
      - C:\Windows\SysWOW64\
  condition: all of selection_* and not 1 of filter_main_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule identifies process execution where iediagcmd.exe or CustomShellHost.exe starts another binary while operating from a WebDAV-related path (e.g., involving \DavWWWRoot\ or UNC paths). The behavior can indicate RCE exploitation using an attacker-controlled WebDAV server to manipulate which executable gets launched, leveraging Windows process start/search behavior. It relies on process creation telemetry, including parent image, current directory, and the spawned child image path, while excluding typical system-binary paths under System32/SysWOW64.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.