// Microsoft 365CRITICAL
XM Cyber disclosed a critical exploit chain affecting Microsoft System Center Configuration Manager (SCCM) that enables remote code execution with SYSTEM privileges. An authenticated domain user without SCCM admin rights can exploit CVE-2026-47301 (broken authorization on AdminService chunked upload) combined with signature validation bypass, path traversal (CabSlip), and unsafe DLL loading to achieve code execution on SCCM primary site servers. Microsoft patched CVE-2026-47301 on July 14, 2026, but related flaws remain unpatched until ConfigMgr 2609 (October 2026).
- Microsoft SCCM Vulnerability Chained to Execute Malicious Code R(opens in a new tab)
- PoC Exploit Released for Microsoft SCCM Vulnerability Enabling S(opens in a new tab)
// Get alerts for Microsoft 365