Microsoft SCCM Flaw Exposes Windows Environments to Remote Attacks
A critical vulnerability in Microsoft's System Center Configuration Manager (SCCM) has been disclosed by security researchers. This flaw allows an attacker to execute malicious code remotely on a SCCM primary site server, potentially taking control of an organization's managed Windows environment.
The attack chain involves several steps, including uploading specially crafted CAB files to the AdminService REST API without proper authorization checks. Researchers identified three weaknesses in the chain: broken authorization, signature validation, and path traversal flaws.
A successful attack can lead to arbitrary file write access on the site's server and execution of malicious code as SYSTEM. Microsoft released a fix for one of the vulnerabilities in July 2026, but the remaining weaknesses are still unpatched and will be addressed in ConfigMgr 2609, expected in October 2026.