logo

SCCM Hierarchy Takeover via Entra Integration…Because of the Implication

ID: 40a3a8e8-9f0f-5d59-b3b5-6bcdbc982760

STIX ID: report--40a3a8e8-9f0f-5d59-b3b5-6bcdbc982760

Feed Name: SpecterOps Blog

Threat Score
75/100

Date Published: 2025-11-19

Date Updated: 2026-04-30

Author: Garrett Foster

...
...

This report analyzes a privilege-escalation vulnerability in Microsoft SCCM's AdminService integration with Entra ID that allowed an attacker who can create or manipulate synchronized UPNs to impersonate Active Directory identities (including the site server machine account) and perform administrative actions across the SCCM hierarchy; the author documents code paths, a proof-of-concept, environment assumptions and caveats, and notes Microsoft patched the issue in hotfix KB35360093 (CVE-2025-59501).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.