Microsoft Configuration Manager CAB Extraction Remote Code Execution Exploit

The module authenticates to Configuration Manager AdminService with a low-privileged domain identity and calls UploadExtensionInChunks. The exploit uses an Authenticode-signed CAB to extract a path traversal to place an adsource.dll proxy and a preserved original DLL in the Configuration Manager bin X64 directory. Active Directory System Discovery subsequently loads the proxy in SMS_EXECUTIVE and modifies the built-in RID-500 account as NT AUTHORITY\\SYSTEM. The module then authenticates over SMB with that local administrator and deploys an Impact agent as SYSTEM. An HTTP 500 response can occur after successful CAB extraction and is therefore not treated as definitive failure. The agent callback is the success condition.
Exploit Platform
Product Name