Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.
Enterprises use Microsoft System Center Configuration Manager ( told CSO.
The revealed attack chain combines four weaknesses, including a broken authorization in the AdminService upload functionality, a path-traversal flaw dubbed “CabSlip,” weak code-signing validation that could be tricked with a $58 commercial certificate, and an unsigned DLL-loading path in the SMS Executive service.
Microsoft fixed the initial authorization flaw, tracked as assignments, particularly accounts with the Operations Administrator role or equivalent Create permissions.
Teams should also monitor the Site Server’s “AdminService.log” for a “System.IO.DirectoryNotFoundException” followed by an HTTP 500 response, a pattern that can indicate the path traversal was triggered, XM Cyber added.
Unexpected modifications to adsource.dll in the Configuration Manager installation directory can provide another detection signal.
Microsoft is reportedly working on patches for the remaining flaws. It did not immediately respond to CSO’s request for comment.
The article originally appeared on CSO.
SOCIAL SHARE CARD GENERATOR