Public proof-of-concept exploit code is now available for CVE-2026-47301, a important distant code execution vulnerability affecting Microsoft Configuration Supervisor (SCCM).
The disclosed exploit chain might enable a low-privileged area person to achieve SYSTEM-level execution on a Configuration Supervisor Major Website Server, making a doubtlessly severe enterprise takeover danger.
Safety researcher Omri Baso published a proof-of-concept repository that features supply code, mission information, a crafted CAB archive, and a compiled launch. The researcher described the problem as a multi-stage exploit chain quite than a single flaw.
Based on the disclosure, CVE-2026-47301 combines damaged entry management, path traversal throughout CAB extraction, arbitrary file write capabilities, certificate-verification bypass, and DLL hijacking.
Collectively, these weaknesses can allow an attacker to position attacker-controlled information into the Configuration Supervisor set up listing and trigger a privileged SCCM service to load them.
Public Exploit Launched for Microsoft SCCM Flaw
The assault targets the SMS_EXECUTIVE service, a core SCCM element that runs with elevated privileges. The revealed analysis states {that a} malicious CAB file can be utilized to jot down DLL information exterior their meant extraction listing by means of traversal sequences.
The information are in the end positioned within the Configuration Supervisor binX64 listing, the place the service can load them. The exploit uses a DLL proxying strategy involving adsource.dll and adsource_original.dll.

GenericAll entry these ending in $ are major website servers (supply: GitHub)The malicious DLL is designed to execute the attacker’s code whereas forwarding anticipated performance to the unique library, lowering the probability of crashing the SCCM service.
The researcher noticed that the related DLL load could happen on a recurring schedule, which means exploitation could not produce fast seen outcomes.
A profitable assault reportedly requires figuring out the SCCM Major Website Server. Though this data will not be immediately published in Active Directory, the researcher mentioned it may be inferred by reviewing permissions on the System Administration container.
Area laptop accounts granted Full Management or GenericAll permissions over that container could point out Configuration Supervisor website servers.
The discharge of useful exploit materials considerably will increase the danger to organizations that haven’t utilized Microsoft’s security updates.
SCCM servers are particularly enticing targets as a result of they handle software program deployment, endpoint configuration, and administrative operations throughout enterprise Home windows environments.
SYSTEM-level code execution on a Primary Site Server might present attackers with a robust platform for lateral motion, malware deployment, credential theft, or ransomware exercise.

Procmon64.exe (supply: GitHub)The revealed demonstration CAB allows and modifies the built-in RID 500 Administrator account as a part of its proof-of-concept conduct.
Defenders ought to deal with the presence of sudden modifications to this account, suspicious DLLs within the Configuration Supervisor set up listing, or uncommon exercise involving CAB uploads as high-priority indicators for investigation.
Organizations utilizing Microsoft Configuration Supervisor ought to instantly evaluate Microsoft’s advisory for CVE-2026-47301, determine uncovered or unpatched Major Website Servers, and apply the related safety replace.
Directors must also prohibit entry to SCCM administration interfaces, audit permissions in Energetic Listing’s System Administration container, and monitor the SMS_EXECUTIVE service for irregular DLL-loading occasions. The general public availability of exploit code modifications this from a patch-management situation into an pressing detection-and-response concern.
Strengthen Your SOC by Accelerating Menace Detection & Speedy Investigations. -> Integrate ANY.RUN With Your SOC Now.