Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Threema Messaging Service Suffers Massive DDoS Attack
August 17, 2026
HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Itself
August 17, 2026
Roundcube Patches Critical RCE and SSRF Vulnerabilities in 1.6.18, 1.7.3
August 17, 2026
Home/CyberSecurity News/Critical Microsoft SCCM Vulnerability Lets Attackers Execute Remote Code
CyberSecurity News

Critical Microsoft SCCM Vulnerability Lets Attackers Execute Remote Code

Key Takeaways A critical attack chain in Microsoft System Center Configuration Manager (SCCM) allows remote code execution on primary site servers. The vulnerabilities, initially reported by XM...

Jennifer sherman
Jennifer sherman
August 17, 2026 3 Min Read
3 0

Key Takeaways

  • A critical attack chain in Microsoft System Center Configuration Manager (SCCM) allows remote code execution on primary site servers.
  • The vulnerabilities, initially reported by XM Cyber, can be triggered by a standard Active Directory domain user without elevated privileges.
  • One critical authorization bypass (CVE-2026-47301) was patched by Microsoft in July 2026, but other elements of the attack chain remain unaddressed.
  • Successful exploitation could lead to full control over an organization’s Windows environment, running malicious code with SYSTEM privileges.

Unpatched SCCM Flaws Enable Remote Code Execution

Cybersecurity researchers have uncovered a severe multi-stage attack chain impacting Microsoft System Center Configuration Manager (SCCM), also known as Configuration Manager. This series of vulnerabilities could enable an attacker to execute arbitrary code remotely on an SCCM primary site server, potentially giving them complete control over an organization’s managed Windows infrastructure.

Table Of Content

  • Key Takeaways
  • Unpatched SCCM Flaws Enable Remote Code Execution
  • The Discovered Vulnerability Chain
  • What You Should Do

The severity of this exploit is heightened by its low barrier to entry: a standard Active Directory domain user, without any SCCM administrative permissions, elevated Windows privileges, or user interaction, can initiate the attack. The target, the SCCM primary site server, is a cornerstone of enterprise IT, responsible for critical functions such as software deployment, patching, OS installation, compliance, and device management.

The Discovered Vulnerability Chain

XM Cyber reported the vulnerabilities to Microsoft on May 23, 2026. Microsoft subsequently assigned CVE-2026-47301 to an authorization bypass component of the chain and released a patch on July 14, 2026. However, XM Cyber researchers note that several other critical weaknesses within the attack chain remain unpatched. Microsoft has indicated these will be addressed in ConfigMgr 2609, anticipated for release in October 2026.

The initial entry point involved a flaw in SCCM’s AdminService REST API. While a standard endpoint for uploading console extension packages via CAB archives correctly enforced role-based access control, a “chunked upload” endpoint failed to perform the same authorization check. This oversight permitted authenticated domain users to upload specially crafted CAB files to the server, bypassing security restrictions.

Another weakness was identified in SCCM’s signature validation process. Although the system verified the presence of an embedded signature within a CAB archive, it reportedly did not confirm that the signing certificate originated from Microsoft or the victim organization. Additionally, certificate revocation checks were bypassed. This allowed attackers to use any valid certificate, even if not trusted, to sign and upload a malicious extension package.

Researchers also discovered a path traversal vulnerability, dubbed “CabSlip.” During CAB archive extraction, SCCM did not adequately prevent relative path sequences. This allowed a maliciously crafted archive to write files outside its designated temporary extraction directory, granting attackers arbitrary file write access on the site server.

The final stage of the attack leveraged a DLL loading vulnerability within the SMS Executive service, which operates with NT AUTHORITYSYSTEM privileges. While the service validates its primary DLL, it loads a secondary DLL named adsource.dll without performing equivalent integrity checks. An attacker could exploit the path traversal flaw to overwrite this adsource.dll. When SCCM later loads the compromised library, the malicious code would execute with SYSTEM privileges, effectively granting full control.

Microsoft’s July update addressed the initial authorization bypass, preventing standard domain users from exploiting the chunked upload endpoint. Nevertheless, users with the built-in Operations Administrator role, or a custom role configured with “Create” permission on the SMS_ConsoleExtensionData object, may still be able to access and exploit the subsequent stages of the attack chain.

What You Should Do

  • Monitor SCCM Logs: Actively review AdminService.log for instances of DirectoryNotFoundException errors followed by HTTP 500 responses. Investigate any suspicious or unexpected CAB upload activity.
  • Inspect adsource.dll: Monitor for unauthorized changes to the adsource.dll file within your Configuration Manager installation directory.
  • Restrict Network Access: Implement strict network access controls for the AdminService port, limiting its exposure to only necessary internal systems.
  • Review Role Assignments: Urgently audit and restrict SCCM role assignments, particularly those with “Create” permission on the SMS_ConsoleExtensionData object, until Microsoft releases a comprehensive fix.
  • Apply Updates: Ensure the July 2026 patch for CVE-2026-47301 is applied immediately. Plan to deploy the ConfigMgr 2609 update promptly when it becomes available in October 2026.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Z.ai Launches GLM-5.3, Boosting Cybersecurity and Coding Capabilities

Next Post

Roundcube Patches Critical RCE and SSRF Vulnerabilities in 1.6.18, 1.7.3

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical GeoServer SQLi Vulnerability Allows Remote Code Execution
August 17, 2026
MessiahGPT AI Model Automates Ransomware and Phishing Attacks
August 17, 2026
Fake Web3 Interview Campaign Delivers NeedleStealer and hVNC RAT via Signed ClickOnce
August 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us