Microsoft’s “Immediate” Retirement of MDT
ID: 93709fef-d82a-5fcd-ac09-fc67d5728bbf
STIX ID: report--93709fef-d82a-5fcd-ac09-fc67d5728bbf
Feed Name: SpecterOps Blog
The report demonstrates how MDT/WDS deployments can be discovered unauthenticated via PXE/TFTP and leveraged through an unauthenticated MDT monitoring API and an XXE flaw to coerce authentication and exfiltrate privileged MDT service account credentials; it includes PoC steps, tooling, a disclosure timeline (Microsoft retired MDT instead of issuing patches), and mitigation guidance such as disabling the monitoring service, tightening share permissions, applying least privilege, and planning migration to supported OSD solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
