Xmcyber
Critical Vulnerabilities in Microsoft SCCM Enable Remote Code Execution for $58
Article Content
Security researchers from XM Cyber have identified a chain of vulnerabilities in Microsoft System Center Configuration Manager (SCCM) that allows standard domain users to achieve remote code execution. The attack exploits multiple flaws, including CVE-2026-47301, which was patched in July 2026, but three additional vulnerabilities remain unaddressed until the upcoming ConfigMgr 2609 release in October. The attack can be initiated by any authenticated user with network access to the SCCM environment, enabling them to gain SYSTEM-level control over the primary site server and all managed endpoints. The vulnerabilities include a broken authorization check, a path traversal flaw dubbed 'CabSlip', and weak code-signing validation that can be bypassed with a $58 certificate. With over 100 million active SCCM users, the potential impact is significant, and organizations are urged to secure their systems against these vulnerabilities.
Key Points: • Standard domain users can exploit SCCM vulnerabilities for remote code execution. • CVE-2026-47301 was patched, but three additional vulnerabilities remain unaddressed. • An attacker can gain SYSTEM-level control over all managed endpoints with network access.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.