Windows: Potential CVE-2025-33053 WebDAV RCE via iediagcmd.exe or CustomShellHost.exe
Flags suspicious child execution from WebDAV/UNC paths initiated by iediagcmd.exe or CustomShellHost.exe, consistent with CVE-2025-33053 exploitation.
FreeUnreviewedSigmahighv1
windows-potential-cve-2025-33053-webdav-rce-via-iediagcmd-exe-or-customshellhost-abe06362
title: "Windows: Potential CVE-2025-33053 WebDAV RCE via iediagcmd.exe or CustomShellHost.exe"
id: a74dc046-3f36-4aa6-adc7-7ee33c05f6b8
related:
- id: 9a2d8b3e-f5a1-4c68-9e21-7d9e1cf8a123
type: similar
- id: 04fc4b22-91a6-495a-879d-0144fec5ec03
type: similar
- id: abe06362-a5b9-4371-8724-ebd00cd48a04
type: derived
status: experimental
description: This rule identifies process execution where iediagcmd.exe or CustomShellHost.exe starts another binary while operating from a WebDAV-related path (e.g., involving \DavWWWRoot\ or UNC paths). The behavior can indicate RCE exploitation using an attacker-controlled WebDAV server to manipulate which executable gets launched, leveraging Windows process start/search behavior. It relies on process creation telemetry, including parent image, current directory, and the spawned child image path, while excluding typical system-binary paths under System32/SysWOW64.
references:
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053
- https://research.checkpoint.com/2025/stealth-falcon-zero-day/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Exploits/CVE-2025-33053/proc_creation_win_exploit_cve_2025_33053.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-06-13
tags:
- attack.command-and-control
- attack.execution
- attack.stealth
- attack.t1218
- attack.lateral-movement
- attack.t1105
- detection.emerging-threats
- cve.2025-33053
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage:
- C:\Program Files\internet explorer\iediagcmd.exe
- C:\Windows\System32\CustomShellHost.exe
selection_child_current_dir:
- CurrentDirectory|startswith: \\\\
- CurrentDirectory|contains: \DavWWWRoot\
- Image|contains: \DavWWWRoot\
- Image|startswith: \\\\
selection_child_img:
Image|endswith:
- \route.exe
- \netsh.exe
- \makecab.exe
- \dxdiag.exe
- \ipconfig.exe
- \explorer.exe
filter_main_system:
Image|startswith:
- C:\Windows\System32\
- C:\Windows\SysWOW64\
condition: all of selection_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule identifies process execution where iediagcmd.exe or CustomShellHost.exe starts another binary while operating from a WebDAV-related path (e.g., involving \DavWWWRoot\ or UNC paths). The behavior can indicate RCE exploitation using an attacker-controlled WebDAV server to manipulate which executable gets launched, leveraging Windows process start/search behavior. It relies on process creation telemetry, including parent image, current directory, and the spawned child image path, while excluding typical system-binary paths under System32/SysWOW64.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.