Microsoft SCCM Vulnerability Chain Could Enable Remote SYSTEM-Level Code Execution
RedSide Security August 17, 2026 Vulnerability 13 views
Security researchers have disclosed an attack chain affecting Microsoft System Center Configuration Manager (SCCM) that could allow standard Active Directory users to ultimately execute malicious code with SYSTEM privileges on an SCCM primary site server. The chain combines an AdminService authorization flaw, weak signature validation, CAB path traversal, and unsafe DLL loading.