logo

The (Static) Keys to Abusing PDQ SmartDeploy

ID: ca993c5d-8192-52f4-a5f7-b5de98d89c14

STIX ID: report--ca993c5d-8192-52f4-a5f7-b5de98d89c14

Feed Name: SpecterOps Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-30

Author: Garrett Foster

...
...

PDQ SmartDeploy prior to version 3.0.2046 used static, hardcoded encryption keys and weak encoding for credential storage in Answer Files, registry entries, and configuration files, enabling low-privileged users or anyone with access to deployment artifacts (WIM images, REMINST shares, or SmartDeploy server files) to decrypt privileged credentials and escalate privileges; proof-of-concept scripts and a disclosure timeline culminating in CVE assignments and a patched release are included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.