Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Microsoft SCCM Flaws Enable Remote Code Execution

Critical Microsoft SCCM Flaws Enable Remote Code Execution

Posted on August 17, 2026 By CWS

Security researchers have recently identified a critical vulnerability chain impacting Microsoft System Center Configuration Manager (SCCM). These flaws present a risk of remote code execution on SCCM primary site servers, potentially compromising an organization’s entire Windows management infrastructure.

Understanding the SCCM Vulnerabilities

The vulnerabilities are particularly alarming because they can be initiated by a standard Active Directory domain user without needing administrative permissions or elevated privileges. This makes the attack vector accessible to many potential bad actors.

The primary target of these attacks is the SCCM primary site server. This server is crucial as it manages software deployment, operating system installations, and compliance monitoring across the network, making it a high-value target for attackers.

Details of the Discovered Flaws

XM Cyber brought these vulnerabilities to Microsoft’s attention on May 23. Microsoft acknowledged the broken authorization issue by assigning it CVE-2026-47301 and provided a fix on July 14, 2026. Despite this, other vulnerabilities in the chain remain unpatched and are expected to be addressed in the upcoming ConfigMgr 2609 update in October 2026.

The first issue involves the SCCM AdminService REST API, where a lack of proper authorization checks at a chunked upload endpoint allows authenticated users to submit malicious CAB files.

Exploiting Weaknesses in SCCM

Another significant flaw is associated with the signature validation process. Although SCCM checks for a valid signature on CAB files, it does not ensure the signing certificate is from trustworthy sources, like Microsoft or the victim organization, nor does it perform certificate revocation checks. This loophole allows attackers to upload harmful extension packages.

Researchers also discovered a path traversal vulnerability, termed “CabSlip,” which allows attackers to write files outside the designated extraction folder, resulting in arbitrary file write access.

The final stage of the attack exploits the SMS Executive service’s DLL loading behavior, enabling attackers to execute malicious code with SYSTEM privileges by replacing a secondary DLL named adsource.dll.

Mitigation and Future Outlook

While Microsoft’s recent updates have blocked some attack paths, particularly for standard domain users at the chunked upload endpoint, certain roles like Operations Administrator can still exploit these vulnerabilities. Organizations are advised to restrict access to the AdminService network port, scrutinize SCCM role assignments, and closely monitor logs for suspicious activities.

Until a comprehensive fix is released, it is crucial for organizations to remain vigilant and implement recommended security measures to mitigate potential risks associated with these SCCM vulnerabilities.

Cyber Security News Tags:Active Directory, AdminService API, attack chain, CAB files, Cybersecurity, DLL loading, Microsoft SCCM, remote code execution, SCCM primary site server, Software Security, Vulnerabilities

Post navigation

Previous Post: Critical Unisoc VoLTE Exploit Grants Kernel Access
Next Post: SAP Commerce Cloud Faces Exploitation After Patch Release

Related Posts

Multiple GitLab Vulnerabilities Let Attackers Inject Malicious Prompts to Steal Sensitive Data Multiple GitLab Vulnerabilities Let Attackers Inject Malicious Prompts to Steal Sensitive Data Cyber Security News
Automaker Boosts SOC Triage with Enhanced Tactics Automaker Boosts SOC Triage with Enhanced Tactics Cyber Security News
Agentless Access, Sensitive Data Masking, and Smooth Session Playback Agentless Access, Sensitive Data Masking, and Smooth Session Playback Cyber Security News
Critical OpenClaw Vulnerability Allows AI Agent Hijacking Critical OpenClaw Vulnerability Allows AI Agent Hijacking Cyber Security News
New Research Unmask DPRK IT Workers Email Address and Hiring Patterns New Research Unmask DPRK IT Workers Email Address and Hiring Patterns Cyber Security News
Janela RAT Malware Targets Latin American Financial Sector Janela RAT Malware Targets Latin American Financial Sector Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical macOS Flaw Exploited to Install Crypto Miner
  • Roundcube Updates Address Critical Security Flaws
  • SAP Commerce Cloud Faces Exploitation After Patch Release
  • Critical Microsoft SCCM Flaws Enable Remote Code Execution
  • Critical Unisoc VoLTE Exploit Grants Kernel Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical macOS Flaw Exploited to Install Crypto Miner
  • Roundcube Updates Address Critical Security Flaws
  • SAP Commerce Cloud Faces Exploitation After Patch Release
  • Critical Microsoft SCCM Flaws Enable Remote Code Execution
  • Critical Unisoc VoLTE Exploit Grants Kernel Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark