It took $58 to break Microsoft’s SCCM, but a patch made it harder
Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment. Enterprises use Microsoft System Center Configuration Manager ( SCCM ) to deploy operating systems, manage patches, distribute software, and monitor compliance across large…
Microsoft's System Center Configuration Manager (SCCM) has been compromised by researchers at XM Cyber, who discovered a four-stage attack chain that can lead to remote code execution. The attack requires network access to the SCCM environment and starts with a standard domain user, who can exploit multiple flaws to achieve code execution as "NT AUTHORITY\SYSTEM" on the primary site server. This would effectively grant attackers access to all of the company's assets.
The initial compromise involves exploiting an authorization flaw in the AdminService upload functionality and a path-traversal flaw, dubbed "CabSlip," which allows attackers to write files outside the intended temporary extraction directory. The attack chain becomes particularly dangerous because SCCM's signature validation does not verify the trustworthiness of the signing certificate.
This means an attacker could use a $58 commercial certificate to bypass trust checks and gain code execution as SYSTEM. Microsoft addressed the initial authorization flaw in July (CVE-2026-47301) but believes that the remaining links in the attack chain will not be fully patched until the ConfigMgr 2609 update, scheduled for October.
Written by urgent.news from Computerworld's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Researcher creates workaround for Microsoft Defender security patch computerworld.com