It took $58 to break Microsoft’s SCCM, but a patch made it harder

Chronological Source Flow
Back

AI Fusion Summary

Researchers at XM Cyber discovered that a standard domain user without Microsoft SCCM privileges can chain multiple flaws to achieve remote code execution. This attack requires network access to the SCCM environment, allowing a user to gain NT AUTHORITY\SYSTEM status on the primary site server. Because enterprises use Microsoft System Center Configuration Manager to manage Windows fleets, compromising the Site Server enables the attacker to compromise all managed clients, potentially leading to the takeover of all company assets.
Community Comments
Loading updates...
0