Xmcyber
Critical Remote Code Execution Flaw in Microsoft SCCM Discovered
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
XM Cyber identified a series of vulnerabilities in Microsoft SCCM that allow standard domain users to achieve remote code execution without administrative privileges. The exploit chain targets the primary site server, potentially compromising all managed clients. The vulnerabilities include a broken authorization check in the AdminService API, a path traversal flaw dubbed 'CabSlip', weak code-signing validation, and an unsigned DLL-loading path. Microsoft assigned CVE-2026-47301 for one of the vulnerabilities, which was patched in July 2026, but the remaining vulnerabilities are unpatched and expected to be addressed in October 2026. The attack can escalate privileges to 'NT AUTHORITY\SYSTEM', affecting over 100 million active users of SCCM. Until the complete fix is released, organizations remain at risk.
Key Points: • A series of vulnerabilities in Microsoft SCCM allows remote code execution by standard users. • CVE-2026-47301 was patched in July, but other vulnerabilities remain unaddressed until October. • The exploit chain can compromise all managed clients once the primary site server is breached.