📰 IT NachrichtenAnthropic C.E.O. Dario Amodei Calls for A.I. Slowdown(12.09.2026 um 18:03 Uhr)
🔧 AI Nachrichten Etzioni on AI: What kids tell chatbots, but not you(04.09.2026 um 16:05 Uhr)
📰 IT NachrichtenAnthropic C.E.O. Dario Amodei Calls for A.I. Slowdown(12.09.2026 um 18:03 Uhr)
🔧 AI Nachrichten Etzioni on AI: What kids tell chatbots, but not you(04.09.2026 um 16:05 Uhr)

📰 IT Nachrichten 🕛 vor 30 Tagen 3 Min Lesezeit CVE-2026-47301
0

It took $58 to break Microsoft’s SCCM, but a patch made it harder

Cyber Threat & Vulnerability Dossier CVSS 9.5 CRITICAL (Heuristik) EPSS 67.8%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔑 Geringe Nutzerrechte nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (computerworld.com)
🔬 IoC Intelligence (1 Indikatoren erkannt)
CVE-2026-47301
🗣️ Stimme:
📑 Inhaltsübersicht








Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.





Enterprises use Microsoft System Center Configuration Manager ( told CSO.





The revealed attack chain combines four weaknesses, including a broken authorization in the AdminService upload functionality, a path-traversal flaw dubbed “CabSlip,” weak code-signing validation that could be tricked with a $58 commercial certificate, and an unsigned DLL-loading path in the SMS Executive service.





Microsoft fixed the initial authorization flaw, tracked as  assignments, particularly accounts with the Operations Administrator role or equivalent Create permissions.





Teams should also monitor the Site Server’s “AdminService.log” for a “System.IO.DirectoryNotFoundException” followed by an HTTP 500 response, a pattern that can indicate the path traversal was triggered, XM Cyber added.





Unexpected modifications to adsource.dll in the Configuration Manager installation directory can provide another detection signal.





Microsoft is reportedly working on patches for the remaining flaws. It did not immediately respond to CSO’s request for comment.





The article originally appeared on CSO.


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf computerworld.com.
↗ Original-Artikel auf computerworld.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Premier League Soccer: Stream Chelsea vs. Hull City Live From Anywhere
1 Quelle
Anthropic C.E.O. Dario Amodei Calls for A.I. Slowdown
1 Quelle
Inside the Discussions at AI Companies Over a Superintelligence Doomsday