CyberSecurity SEE

$58 Was Enough to Exploit Microsoft’s SCCM, But a Patch Made It More Difficult

 Was Enough to Exploit Microsoft’s SCCM, But a Patch Made It More Difficult

Recent cybersecurity reports have unveiled a concerning attack chain that exploits multiple vulnerabilities, posing significant risks to Microsoft System Center Configuration Manager (SCCM) users. This series of weaknesses includes a broken authorization in the AdminService upload feature, a path-traversal flaw famously named “CabSlip,” inadequate code-signing validation, and an unsigned Dynamic Link Library (DLL) loading path associated with the SMS Executive service. Together, these vulnerabilities create a pathway for potential cyber intruders to gain unauthorized access and execute harmful actions within affected systems.

### Identifying the Vulnerabilities

The vulnerabilities identified consist of several distinct but interconnected issues. One of the most critical flaws is a broken authorization mechanism within the AdminService upload functionality, which has been referenced as CVE-2026-47301. Microsoft has acknowledged this issue and applied a fix in July of this year. However, other components of the attack chain remain unresolved and are not anticipated to be fully addressed until the introduction of ConfigMgr 2609, scheduled for release in October.

The primary threat vector starts with the AdminService API, which is an essential part of SCCM’s functionality. Under normal circumstances, the extension-upload endpoint effectively verifies user permissions before allowing file uploads. However, the “chunked-upload” variant of this API bypasses this critical permission check. This oversight allows authenticated Active Directory users—even those without administrative privileges—to upload a malicious CAB archive to the system, thus creating an initial foothold for an attack.

### The Role of CabSlip

Another notable weakness is referred to as “CabSlip,” a path-traversal flaw that could be exploited alongside other vulnerabilities in the attack chain. Path traversal vulnerabilities generally allow attackers to read sensitive files on the server or system where the program is running. In this instance, it creates further exploitative opportunities for malicious actors following the initial upload of a compromised CAB archive.

Furthermore, weak code-signing validation adds yet another layer of risk. According to cybersecurity experts, this vulnerability can be manipulated using a readily available $58 commercial certificate. Unsurprisingly, this affordable entry point for attackers raises grave concerns about the barriers to entry for hostile entities looking to compromise systems. This highlights a significant gap in the existing security measures that organizations usually rely on to validate the integrity of software and updates before they are installed.

### DLL Loading Path Risks

Additionally, the flaws extend to the SMS Executive service, which contains an unsigned DLL-loading path. If attackers manage to exploit vulnerabilities within the SMS Executive service, they could potentially load malicious DLLs without detection, leading to unauthorized actions being executed on compromised systems. This lack of proper signing opens avenues for further exploitation and heightens the risks associated with the other vulnerabilities in play.

### Implications for Users and Organizations

The implications of these vulnerabilities are profound, particularly for organizations that rely heavily on SCCM for their system management and configuration tasks. With the potential for unauthorized users to upload malicious files and execute harmful operations, there is an urgent need for companies to evaluate their security postures. Organizations using SCCM must prioritize applying existing patches, especially the CVE-2026-47301 fix, while remaining vigilant about the remaining vulnerabilities that will not be addressed until the upcoming ConfigMgr update.

In light of these findings, experts emphasize the importance of comprehensive security verification and proactive monitoring of systems. Organizations should also consider implementing additional layers of security and risks assessments to bolster defenses against potential exploitations stemming from vulnerabilities.

### Conclusion

The reveal of this attack chain serves as a clarion call for immediate action among SCCM users. The combination of a broken authorization mechanism, the CabSlip path traversal flaw, weak code-signing validation, and an unsigned DLL loading path underscores a widespread issue within Microsoft’s system management tools. As pending updates draw nearer, cybersecurity professionals and organizations must remain attentive to these vulnerabilities to prevent potential breaches and safeguard critical infrastructure from malicious threats.

Source link

Exit mobile version