The module authenticates to Configuration Manager AdminService with a low-privileged domain identity and calls UploadExtensionInChunks. The exploit uses an Authenticode-signed CAB to extract a path traversal to place an adsource.dll proxy and a preserved original DLL in the Configuration Manager bin X64 directory. Active Directory System Discovery subsequently loads the proxy in SMS_EXECUTIVE and modifies the built-in RID-500 account as NT AUTHORITY\\SYSTEM. The module then authenticates over SMB with that local administrator and deploys an Impact agent as SYSTEM. An HTTP 500 response can occur after successful CAB extraction and is therefore not treated as definitive failure. The agent callback is the success condition.
CVE Link
Exploit Platform
Exploit Type
Product Name