GuidePoint Security has unveiled the discovery of an undocumented way to compromise an account and elevate privileges inside an SCCM (System Center Configuration Manager) – aka Microsoft Endpoint Configuration Manager (MECM) – network.
GuidePoint Security’s Threat & Attack Simulation (TAS) team detected SCCM exploitation for account compromise, finding the conditions that can compromise SCCM client push and machine accounts through automatic site-wide client push installation and Active Directory system discovery.
Due to the permissions these accounts hold, this can lead to an SCCM site takeover or, in the case of the SCCM push account, administrative privileges over numerous computer objects within the domain.
The TAS researchers are the first to find this novel attack path across the industry in SCCM, an endpoint management tool.
With certain conditions explained, an attacker may be able to retrieve the hashed credentials for all configured SCCM push accounts, meaning they may be able to access admin privileges.
You can read about this here.
Related
This entry was posted on March 28, 2024 at 8:31 am and is filed under Commentary with tags GuidePoint. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
New Attack Path Exploits Microsoft SCCM: Researchers Discover Undocumented Way to Compromise Account Privileges
GuidePoint Security has unveiled the discovery of an undocumented way to compromise an account and elevate privileges inside an SCCM (System Center Configuration Manager) – aka Microsoft Endpoint Configuration Manager (MECM) – network.
GuidePoint Security’s Threat & Attack Simulation (TAS) team detected SCCM exploitation for account compromise, finding the conditions that can compromise SCCM client push and machine accounts through automatic site-wide client push installation and Active Directory system discovery.
Due to the permissions these accounts hold, this can lead to an SCCM site takeover or, in the case of the SCCM push account, administrative privileges over numerous computer objects within the domain.
The TAS researchers are the first to find this novel attack path across the industry in SCCM, an endpoint management tool.
With certain conditions explained, an attacker may be able to retrieve the hashed credentials for all configured SCCM push accounts, meaning they may be able to access admin privileges.
You can read about this here.
Share this:
Like this:
Related
This entry was posted on March 28, 2024 at 8:31 am and is filed under Commentary with tags GuidePoint. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.